CVE-2017-12857: Polycom Unified Communications Software

High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.

Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affected by a vulnerability in their UCS web application. This vulnerability could allow an authenticated remote attacker to read a segment of the phone's memory which could contain an administrator's password or other sensitive information.

Affected products

  • Polycom Unified Communications Software: up to and including 4.0.11; up to and including 5.4.6; up to and including 5.5.1; up to and including 5.4.4

Published 2017-08-25. Last modified 2026-06-17.