CVE-2018-18566: Polycom Unified Communications Software
Medium severity, CVSS 5.3. EPSS: 2.8% chance of exploitation in the next 30 days.
The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Business.
Affected products
- Polycom Unified Communications Software: up to and including 5.8.0.12848
- Polycom Vvx 500 Firmware: affected versions not specified
- Polycom Vvx 601 Firmware: affected versions not specified
Published 2018-10-24. Last modified 2026-06-17.