An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as admin without authentication.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-07-17T22:01:38

Updated: 2024-08-03T05:03:32.955Z

Reserved: 2022-03-04T00:00:00

Link: CVE-2022-26479

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-07-17T23:15:08.403

Modified: 2022-07-22T13:25:32.397

Link: CVE-2022-26479

cve-icon Redhat

No data.