Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password reset process.
Link | Tags |
---|---|
https://support.polycom.com/content/support.html | vendor advisory |
https://packetstormsecurity.com/files/140753/Polycom-VVX-Web-Interface-Privilege-Escalation.html | third party advisory vdb entry exploit |