Vulnerability Details CVE-2012-4970
Cross-site scripting (XSS) vulnerability in the web management interface on Polycom HDX Video End Points with UC APL software before 2.7.1.1_J, and commercial software before 3.0.5, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 48.7%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2012-4970
-
cpe:2.3:a:polycom:hdx_system_software:2.0.5_j
-
cpe:2.3:a:polycom:hdx_system_software:2.5.0.7
-
cpe:2.3:a:polycom:hdx_system_software:2.5.0.7_g
-
cpe:2.3:a:polycom:hdx_system_software:2.6.1
-
cpe:2.3:a:polycom:hdx_system_software:2.6.1.3
-
cpe:2.3:a:polycom:hdx_system_software:2.7.0_j
-
cpe:2.3:a:polycom:hdx_system_software:2.7.1_j
-
cpe:2.3:a:polycom:hdx_system_software:3.0.0
-
cpe:2.3:a:polycom:hdx_system_software:3.0.0.1
-
cpe:2.3:a:polycom:hdx_system_software:3.0.0.2
-
cpe:2.3:a:polycom:hdx_system_software:3.0.1
-
cpe:2.3:a:polycom:hdx_system_software:3.0.2
-
cpe:2.3:a:polycom:hdx_system_software:3.0.3
-
cpe:2.3:a:polycom:hdx_system_software:3.0.3.1
-
cpe:2.3:a:polycom:hdx_system_software:3.0.4
-
cpe:2.3:h:polycom:hdx_4002:-
-
cpe:2.3:h:polycom:hdx_4500:-
-
cpe:2.3:h:polycom:hdx_6000:-
-
cpe:2.3:h:polycom:hdx_7001:-
-
cpe:2.3:h:polycom:hdx_7002:-
-
cpe:2.3:h:polycom:hdx_8002:-
-
cpe:2.3:h:polycom:hdx_8004:-
-
cpe:2.3:h:polycom:hdx_8006:-
-
cpe:2.3:h:polycom:hdx_9002:-
-
cpe:2.3:h:polycom:hdx_9004:-
-
cpe:2.3:h:polycom:hdx_9006:-