CVE-2019-3702: Lifesize Icon 300 Firmware

High severity, CVSS 8.8. EPSS: 5.2% chance of exploitation in the next 30 days.

A Remote Code Execution issue in the DNS Query Web UI in Lifesize Icon LS_RM3_3.7.0 (2421) allows remote authenticated attackers to execute arbitrary commands via a crafted DNS Query address field in a JSON API request.

Affected products

  • Lifesize Icon 300 Firmware: version ls_rm3_3.7.0(2421) only
  • Lifesize Icon 500 Firmware: version ls_rm3_3.7.0(2421) only
  • Lifesize Icon 700 Firmware: version ls_rm3_3.7.0(2421) only

Published 2019-05-13. Last modified 2026-06-17.