A vulnerability was discovered in the firmware builds up to 8.2.1.0820 in certain Poly devices. The firmware flaw does not properly prevent path traversal and could lead to information disclosure.
History

Thu, 27 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was discovered in the firmware builds up to 8.2.1.0820 in Poly Edge E devices. The firmware flaw does not properly prevent path traversal and could lead to information disclosure. A vulnerability was discovered in the firmware builds up to 8.2.1.0820 in certain Poly devices. The firmware flaw does not properly prevent path traversal and could lead to information disclosure.
Title Edge E – Path Traversal Vulnerability - Arbitrary File Access by Unauthorized User Certain Poly Devices – Path Traversal Vulnerability - Arbitrary File Access by Unauthorized User

Wed, 05 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Feb 2025 16:00:00 +0000

Type Values Removed Values Added
Title Edge E – Path Traversal Vulnerability - Arbitrary File Access by Unauthorized User
Metrics cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}

cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}


Wed, 05 Feb 2025 15:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was discovered in the firmware builds up to 8.2.1.0820 in Poly Edge E devices. The firmware flaw does not properly prevent path traversal and could lead to information disclosure.
Weaknesses CWE-35
References
Metrics cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2025-03-27T13:32:17.477Z

Reserved: 2025-01-29T19:53:40.452Z

Link: CVE-2025-0858

cve-icon Vulnrichment

Updated: 2025-02-05T15:53:46.347Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-05T15:15:21.580

Modified: 2025-03-27T14:15:21.803

Link: CVE-2025-0858

cve-icon Redhat

No data.