{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-4467","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2023-08-21T17:04:04.338Z","datePublished":"2023-12-29T09:38:03.884Z","dateUpdated":"2024-08-02T07:31:05.430Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2024-01-09T16:16:24.466Z"},"title":"Poly Trio 8800 Test Automation Mode backdoor","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-912","lang":"en","description":"CWE-912 Backdoor"}]}],"affected":[{"vendor":"Poly","product":"Trio 8800","versions":[{"version":"7.2.6.0019","status":"affected"}],"modules":["Test Automation Mode"]}],"descriptions":[{"lang":"en","value":"A vulnerability was found in Poly Trio 8800 7.2.6.0019 and classified as critical. Affected by this issue is some unknown functionality of the component Test Automation Mode. The manipulation leads to backdoor. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249260."},{"lang":"de","value":"Eine Schwachstelle wurde in Poly Trio 8800 7.2.6.0019 gefunden. Sie wurde als kritisch eingestuft. Davon betroffen ist unbekannter Code der Komponente Test Automation Mode. Dank der Manipulation mit unbekannten Daten kann eine backdoor-Schwachstelle ausgenutzt werden. Ein Angriff setzt physischen Zugriff auf dem Zielobjekt voraus. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV3_1":{"version":"3.1","baseScore":6.2,"vectorString":"CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":6.2,"vectorString":"CVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":6.5,"vectorString":"AV:L/AC:L/Au:M/C:C/I:C/A:C"}}],"timeline":[{"time":"2023-12-29T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2023-12-29T01:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2024-01-09T17:12:53.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"Christoph Wolff","type":"finder"},{"lang":"en","value":"Pascal Zenker","type":"finder"}],"references":[{"url":"https://vuldb.com/?id.249260","tags":["vdb-entry"]},{"url":"https://vuldb.com/?ctiid.249260","tags":["signature","permissions-required"]},{"url":"https://modzero.com/en/advisories/mz-23-01-poly-voip/","tags":["related"]},{"url":"https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices","tags":["exploit"]},{"url":"https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html","tags":["related"]}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T07:31:05.430Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.249260","tags":["vdb-entry","x_transferred"]},{"url":"https://vuldb.com/?ctiid.249260","tags":["signature","permissions-required","x_transferred"]},{"url":"https://modzero.com/en/advisories/mz-23-01-poly-voip/","tags":["related","x_transferred"]},{"url":"https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices","tags":["exploit","x_transferred"]},{"url":"https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html","tags":["related","x_transferred"]}]}]}}