Description
The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities.
Published: 2026-07-01
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when Poly Voice IP devices CCX, Trio, and Edge E receive malformed SIP packets from a malicious server. The faulty packet handling causes uncontrolled resource consumption, leading to a crash or hang that renders the device inoperable, thus denying legitimate voice traffic.

Affected Systems

HP Inc. devices identified as CCX, Edge E, and Trio C60 are potentially affected. The CVE does not list specific firmware revisions; any device running the firmware referenced in the HP advisory may be vulnerable.

Risk and Exploitability

The CVSS score of 8.2 indicates a high‑severity remote denial‑of‑service vulnerability. The EPSS score of less than 1% suggests that exploitation is rare and has not been widely reported. The vulnerability is not listed in the CISA KEV catalog. It is inferred that an attacker would need to host or control a SIP server that a device contacts and then send specially crafted malformed packets to trigger excessive resource usage, causing the device to crash or hang and deny service.

Generated by OpenCVE AI on July 21, 2026 at 14:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to the latest HP release that includes the patch for this vulnerability.
  • Restrict inbound SIP traffic to trusted servers or IP ranges using access control lists.
  • Place the devices on isolated VLANs or segment the network to contain potential service disruptions and monitor logs for abnormal SIP activity.

Generated by OpenCVE AI on July 21, 2026 at 14:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities.
Title Poly Voice Devices (CCX, Trio, Edge E) – Potential Denial of Service
Weaknesses CWE-400
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-07-01T14:55:54.454Z

Reserved: 2026-02-20T17:49:42.020Z

Link: CVE-2026-2891

cve-icon Vulnrichment

Updated: 2026-07-01T14:55:48.943Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T14:30:08Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption