CVE-2018-18566: Polycom Unified Communications Software

Medium severity, CVSS 5.3. EPSS: 2.8% chance of exploitation in the next 30 days.

The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Business.

Affected products

  • Polycom Unified Communications Software: up to and including 5.8.0.12848
  • Polycom Vvx 500 Firmware: affected versions not specified
  • Polycom Vvx 601 Firmware: affected versions not specified

Published 2018-10-24. Last modified 2026-06-17.