The Bluetooth subsystem on Polycom Trio devices with software before 5.5.4 has Incorrect Access Control. An attacker can connect without authentication and subsequently record audio from the device microphone.
References
| Link | Resource |
|---|---|
| https://support.polycom.com/content/dam/polycom-support/global/documentation/bluetooth-authentication-weakness-trio.pdf | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2018-11-15 20:29
Updated : 2019-10-03 00:03
NVD link : CVE-2018-14934
Mitre link : CVE-2018-14934
CVE.ORG link : CVE-2018-14934
JSON object : View
Products Affected
polycom
- trio_8500
- trio_8500_firmware
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
