Accessibility Skip to content

Poly ZTP - Exposure of Sensitive Information to an Unauthorized Actor

Vulnerability Summary

A vulnerability in the Poly Zero Touch Provisioning (ZTP) solution could allow an authenticated, remote attacker to obtain pre-provisioning information.

 

Details

CVE 2022-26881 – Poly ZTP Exposure of Sensitive Information to an Unauthorized Actor

A successful exploit could allow the attacker to extract pre-provisioning information, including the provisioning server address and other device provisioning information.

Published

Last Update: 3/10/2022
Initial Public Release: 2/22/2021
Advisory ID:  PLYGN21-02

CVE ID: CVE-2022-26881
CVSS Score: 5.8
CVSS:3.1 /AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

Product Affected
PRODUCTS FIRMWARE FIX
Poly ZTP N/A Integrated
Solution

Poly has added additional monitoring and active blocking updates to mitigate this vulnerability. Poly will be making further enhancements to the ZTP service to enhance security of the service.

 

Workaround

There is no workaround.

Contact

Any customer using an affected system who is concerned about this vulnerability within their deployment should contact Poly Technical Support(888) 248-4143, (916) 928-7561, or visit the Poly Support Site.

 

Revision History
VERSON DATE DESCRIPTION
1.0 2/22/2021 Initial Release
2.0 3/10/2022 Formatting Changes