The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Business.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-028.txt | third party advisory exploit |
http://www.securityfocus.com/bid/105746 | vdb entry third party advisory |
https://seclists.org/bugtraq/2018/Oct/33 | mailing list exploit third party advisory |