CVE-2018-17875

HIGHCVSS 8.8/10EPSS 2.68%

Last modified

CVE-2018-17875 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commands via unspecified vectors.. EPSS estimates a 2.68% chance of exploitation in the next 30 days.

Description

A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commands via unspecified vectors.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
2.68%

83.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
PolyTrio 8800 Firmware5.4.0.12197
PolyTrio 8800 Firmware5.4.0.12541
PolyTrio 8800 Firmware5.4.0.12856
PolyTrio 8800 Firmware5.4.1.17597
PolyTrio 8800 Firmware5.4.2.5400
PolyTrio 8800 Firmware5.4.3.2007
PolyTrio 8800 Firmware5.4.3.2389
PolyTrio 8800 Firmware5.4.3.2400
PolyTrio 8800 Firmware5.4.4.7511
PolyTrio 8800 Firmware5.4.4.7609
PolyTrio 8800 Firmware5.4.4.7776
PolyTrio 8800 Firmware5.4.5.9111
PolyTrio 8800 Firmware5.4.5.9658
PolyTrio 8800 Firmware5.5.2.11338
PolyTrio 8800 Firmware5.5.2.11391
PolyTrio 8800 Firmware5.5.3.3441
PolyTrio 8800 Firmware5.5.3.3517
PolyTrio 8800 Firmware5.5.4.2255
PolyTrio 8800 Firmware5.7.1.4095
PolyTrio 8800 Firmware5.7.1.4133
PolyTrio 8800 Firmware5.7.1.4145

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-17875?
A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commands via unspecified vectors.
How severe is CVE-2018-17875?
CVE-2018-17875 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 2.68% probability of exploitation in the next 30 days.
How do I fix CVE-2018-17875?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-17875?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST