CVE-2018-18568: Polycom Unified Communications Software

Medium severity, CVSS 5.9. EPSS: 0.7% chance of exploitation in the next 30 days.

Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging failure to validate X.509 certificates when used with an on-premise installation with Skype for Business.

Affected products

  • Polycom Unified Communications Software: up to and including 5.8.0.12848
  • Polycom Vvx 500 Firmware: affected versions not specified
  • Polycom Vvx 601 Firmware: affected versions not specified

Published 2018-10-24. Last modified 2026-06-17.