CVE-2012-4970: Polycom Hdx System Software

Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in the web management interface on Polycom HDX Video End Points with UC APL software before 2.7.1.1_J, and commercial software before 3.0.5, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected products

  • Polycom Hdx System Software: up to and including 2.7.1_j; version 2.0.5_j only; version 2.5.0.7 only; version 2.5.0.7_g only; version 2.6.1 only; version 2.6.1.3 only; …

Published 2013-01-01. Last modified 2026-06-16.