{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-21T21:51:30.166","vulnerabilities":[{"cve":{"id":"CVE-2023-4466","sourceIdentifier":"cna@vuldb.com","published":"2023-12-29T10:15:12.470","lastModified":"2026-06-17T06:37:53.637","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability has been found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Interface. The manipulation leads to protection mechanism failure. The attack can be launched remotely. The vendor explains that they do not regard this as a vulnerability as this is a feature that they offer to their customers who have a variety of environmental needs that are met through different firmware builds. To avoid potential roll-back attacks, they remove vulnerable builds from the public servers as a remediation effort. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249259."},{"lang":"es","value":"Una vulnerabilidad fue encontrada en Poly CCX 400, CCX 600, Trio 8800 y Trio C60 y clasificada como problemática. Una función desconocida del componente Web Interface es afectada por esta vulnerabilidad. La manipulación provoca el fallo del mecanismo de protección. El ataque se puede lanzar de forma remota. El proveedor explica que no consideran esto como una vulnerabilidad, ya que es una característica que ofrecen a sus clientes que tienen una variedad de necesidades ambientales que se satisfacen a través de diferentes versiones de firmware. Para evitar posibles ataques de reversión, eliminan las compilaciones vulnerables de los servidores públicos como esfuerzo de remediación. La explotación ha sido divulgada al público y puede utilizarse. El identificador asociado de esta vulnerabilidad es VDB-249259."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"Poly","product":"CCX 400","modules":["Web Interface"],"versions":[{"version":"n/a","status":"affected"}]},{"vendor":"Poly","product":"CCX 600","modules":["Web Interface"],"versions":[{"version":"n/a","status":"affected"}]},{"vendor":"Poly","product":"Trio 8800","modules":["Web Interface"],"versions":[{"version":"n/a","status":"affected"}]},{"vendor":"Poly","product":"Trio C60","modules":["Web Interface"],"versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:M/C:N/I:P/A:N","baseScore":3.3,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"MULTIPLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.4,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-693"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:poly:ccx_400_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"E6EF5E6E-D387-4EB1-A533-C005F76F49E0"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:poly:ccx_400:-:*:*:*:*:*:*:*","matchCriteriaId":"74C09FB0-DC34-4F03-8560-B607FB8A5245"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:poly:ccx_600_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"37A9DF12-51BF-4E6A-B753-7481C95F22AD"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:poly:ccx_600:-:*:*:*:*:*:*:*","matchCriteriaId":"8F8D61E7-160F-4E4F-8C73-724DFF3F92C2"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:poly:trio_8800_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"6307C9DD-572F-44E4-ADCD-205CC1553774"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:poly:trio_8800:-:*:*:*:*:*:*:*","matchCriteriaId":"39862A32-5AF6-41F9-9C25-9D68EB3784DC"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:poly:trio_c60_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"3CC00989-4E87-48F1-9EC9-53F0AB4F445C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:poly:trio_c60:-:*:*:*:*:*:*:*","matchCriteriaId":"6CDD2376-BD9D-4B5E-B776-0F627D09E025"}]}]}],"references":[{"url":"https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html","source":"cna@vuldb.com","tags":["Not Applicable"]},{"url":"https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices","source":"cna@vuldb.com"},{"url":"https://modzero.com/en/advisories/mz-23-01-poly-voip/","source":"cna@vuldb.com"},{"url":"https://vuldb.com/?ctiid.249259","source":"cna@vuldb.com","tags":["Permissions Required","Third Party Advisory","VDB Entry"]},{"url":"https://vuldb.com/?id.249259","source":"cna@vuldb.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"]},{"url":"https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://modzero.com/en/advisories/mz-23-01-poly-voip/","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://vuldb.com/?ctiid.249259","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory","VDB Entry"]},{"url":"https://vuldb.com/?id.249259","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]}]}}]}