CVE-2012-6609: Polycom Hdx Video End Points

High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.

Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.

Affected products

  • Polycom Hdx Video End Points: before 3.0.4 (fixed in 3.0.4)
  • Polycom Uc Apl: before 2.7.1.j (fixed in 2.7.1.j)

Published 2020-01-28. Last modified 2026-06-16.