Poly ZTP - Exposure of Sensitive Information to an Unauthorized Actor
Vulnerability Summary
A vulnerability in the Poly Zero Touch Provisioning (ZTP) solution could allow an authenticated, remote attacker to obtain pre-provisioning information.
Details
CVE 2022-26881 – Poly ZTP Exposure of Sensitive Information to an Unauthorized Actor
A successful exploit could allow the attacker to extract pre-provisioning information, including the provisioning server address and other device provisioning information.
Published
Last Update: 3/10/2022
Initial Public Release: 2/22/2021
Advisory ID: PLYGN21-02
CVE ID: CVE-2022-26881
CVSS Score: 5.8
CVSS:3.1 /AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
Product Affected
PRODUCTS | FIRMWARE | FIX |
---|---|---|
Poly ZTP | N/A | Integrated |
Solution
Poly has added additional monitoring and active blocking updates to mitigate this vulnerability. Poly will be making further enhancements to the ZTP service to enhance security of the service.
Workaround
There is no workaround.
Contact
Any customer using an affected system who is concerned about this vulnerability within their deployment should contact Poly Technical Support – (888) 248-4143, (916) 928-7561, or visit the Poly Support Site.
Revision History
VERSON | DATE | DESCRIPTION |
---|---|---|
1.0 | 2/22/2021 | Initial Release |
2.0 | 3/10/2022 | Formatting Changes |