CVE-2022-26481

An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:poly:studio_x30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:studio_x30:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:poly:studio_x70_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:studio_x70:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:poly:g7500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:g7500:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:poly:studio_x50_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:studio_x50:-:*:*:*:*:*:*:*

Information

Published : 2022-07-17 16:15

Updated : 2022-07-21 15:46


NVD link : CVE-2022-26481

Mitre link : CVE-2022-26481


JSON object : View

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Advertisement

dedicated server usa

Products Affected

poly

  • g7500_firmware
  • studio_x70
  • g7500
  • studio_x70_firmware
  • studio_x50
  • studio_x50_firmware
  • studio_x30_firmware
  • studio_x30