Impact
The vulnerability arises when Poly Voice IP devices CCX, Trio, and Edge E receive malformed SIP packets from a malicious server. The faulty packet handling causes uncontrolled resource consumption, leading to a crash or hang that renders the device inoperable, thus denying legitimate voice traffic.
Affected Systems
HP Inc. devices identified as CCX, Edge E, and Trio C60 are potentially affected. The CVE does not list specific firmware revisions; any device running the firmware referenced in the HP advisory may be vulnerable.
Risk and Exploitability
The CVSS score of 8.2 indicates a high‑severity remote denial‑of‑service vulnerability. The EPSS score of less than 1% suggests that exploitation is rare and has not been widely reported. The vulnerability is not listed in the CISA KEV catalog. It is inferred that an attacker would need to host or control a SIP server that a device contacts and then send specially crafted malformed packets to trigger excessive resource usage, causing the device to crash or hang and deny service.
OpenCVE Enrichment