CVE-2019-11355
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Poly (formerly Polycom) HDX 3.1.13. A feature exists that allows the creation of a server / client certificate, or the upload of the user certificate, on the administrator's page. The value received from the user is the factor value of a shell script on the equipment. By entering a special character (such as a single quote) in a CN or other CSR field, one can insert a command into a factor value. A system command can be executed as root.
Se detectó un problema en Poly (antes Polycom) HDX versión 3.1.13. Existe una funcionalidad que permite la creación de un certificado de servidor/cliente, o la carga del certificado de usuario, en la página del administrador. El valor recibido del usuario es el valor del factor de un script de shell en el equipo. Mediante la introducción de un carácter especial (tal y como una comilla simple) en un campo CN u otro CSR, puede ser insertado un comando en un valor del factor. Un comando de sistema puede ser ejecutado como root.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-04-19 CVE Reserved
- 2020-03-12 CVE Published
- 2024-08-04 CVE Updated
- 2025-05-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.polycom.com/content/dam/polycom-support/global/documentation/hdx-3-1-14-advisory.pdf | 2020-03-18 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Polycom Search vendor "Polycom" | Hdx System Software Search vendor "Polycom" for product "Hdx System Software" | <= 3.1.13 Search vendor "Polycom" for product "Hdx System Software" and version " <= 3.1.13" | - |
Affected
|