CVE-2025-14432
Poly Video - Sensitive Data Might Be Written to Log File
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.1EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
16 dic 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is limited to Microsoft TAC and does not affect configuration changes made using the provisioning server or the device WebUI.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Productos afectados
HP Inc · Polycom EagleEye IVHP Inc · Poly EagleEye CubeHP Inc · Poly G7500HP Inc · Poly Studio A2HP Inc · Poly Studio E60HP Inc · Poly Studio E70HP Inc · Poly Studio G62HP Inc · Poly Studio USBHP Inc · Poly Studio X30HP Inc · Poly Studio X32HP Inc · Poly Studio X50HP Inc · Poly Studio X52HP Inc · Poly Studio X70HP Inc · Poly Studio X72HP Inc · TC10HP Inc · TC8¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →