Description
The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities.
Published: 2026-07-01
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when Poly Voice IP devices – HP Inc’s CCX, Trio C60, and Edge E – receive malformed SIP packets from a malicious SIP server. Improper handling of these packets can cause uncontrolled resource consumption, leading the device to crash or hang and thereby disabling all voice traffic. The weakness is a resource‑consumption flaw (CWE-400) that enables a remote denial‑of‑service attack.

Affected Systems

HP Inc. devices identified as CCX, Edge E, and Trio C60 are potentially affected. The CVE does not specify firmware revisions, so any unit running the firmware referenced in HP’s advisory may be vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 8.2 signals a high‑severity remote denial‑of‑service vulnerability. The EPSS score of less than 1 % indicates a low probability of exploitation, and the vulnerability is not currently cataloged in CISA’s Knowing Exploited Vulnerabilities list. Attackers would need to control a SIP server that a device connects to, then transmit specially crafted malformed packets to trigger excessive resource usage, causing the device to become inoperable.

Generated by OpenCVE AI on August 1, 2026 at 23:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to the latest HP release that contains the fix.
  • Restrict inbound SIP traffic to known, trusted servers or IP ranges using access‑control lists.
  • Place affected devices on isolated VLANs or segment the network to contain potential service disruptions and monitor system logs for abnormal SIP activity.

Generated by OpenCVE AI on August 1, 2026 at 23:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Hp
Hp ccx
Hp edge E
Hp trio C60
Vendors & Products Hp
Hp ccx
Hp edge E
Hp trio C60

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities.
Title Poly Voice Devices (CCX, Trio, Edge E) – Potential Denial of Service
Weaknesses CWE-400
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-07-01T14:55:54.454Z

Reserved: 2026-02-20T17:49:42.020Z

Link: CVE-2026-2891

cve-icon Vulnrichment

Updated: 2026-07-01T14:55:48.943Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T23:30:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption