CVE-2019-12948: Polycom Unified Communications Software

High severity, CVSS 8.3. EPSS: 1.7% chance of exploitation in the next 30 days.

A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin privileges to cause a denial of service (DoS) condition or execute arbitrary code.

Affected products

  • Polycom Unified Communications Software: before 5.8.5.1256 (fixed in 5.8.5.1256); from 5.9.3, before 5.9.3.2857 (fixed in 5.9.3.2857); from 6.0.0, before 6.0.0.4839 (fixed in 6.0.0.4839)
  • Polycom United Communications Software: before 5.9.0 (fixed in 5.9.0); before 4.0.14.1580 (fixed in 4.0.14.1580)

Published 2019-07-29. Last modified 2026-06-17.