Impact
The vulnerability arises when Poly Voice IP devices – HP Inc’s CCX, Trio C60, and Edge E – receive malformed SIP packets from a malicious SIP server. Improper handling of these packets can cause uncontrolled resource consumption, leading the device to crash or hang and thereby disabling all voice traffic. The weakness is a resource‑consumption flaw (CWE-400) that enables a remote denial‑of‑service attack.
Affected Systems
HP Inc. devices identified as CCX, Edge E, and Trio C60 are potentially affected. The CVE does not specify firmware revisions, so any unit running the firmware referenced in HP’s advisory may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 8.2 signals a high‑severity remote denial‑of‑service vulnerability. The EPSS score of less than 1 % indicates a low probability of exploitation, and the vulnerability is not currently cataloged in CISA’s Knowing Exploited Vulnerabilities list. Attackers would need to control a SIP server that a device connects to, then transmit specially crafted malformed packets to trigger excessive resource usage, causing the device to become inoperable.
OpenCVE Enrichment