Impact
The flaw is a Cross‑Site Request Forgery that allows an attacker who has acquired a valid session cookie for a Poly Voice IP phone to submit requests that overwrite or alter the device’s WebUI pages. The description indicates that modifications are limited to the contents of the WebUI and does not mention arbitrary code execution or firmware compromise, so the primary impact is unauthorized configuration changes visible through the web interface.
Affected Systems
Affected hardware includes HP Inc. Poly CCX, Poly Edge E, and Poly Trio C60 IP phones. The CNA does not disclose specific firmware versions; therefore, any device in those families that has not applied the vendor’s patch may be vulnerable.
Risk and Exploitability
The CVSS score of 6.0 classifies the flaw as moderate severity, while the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV database. Exploitation requires the attacker to first obtain a valid session cookie, typically through phishing, social engineering, or network interception, after which the attacker can craft HTTP requests that are accepted by the WebUI, potentially changing displayed or stored configuration data. The likely attack vector is a stolen authenticated session.
OpenCVE Enrichment