CVE-2018-15128
9.8
CRITICAL · CVSS 3.0 · EPSS 5.2% (pctl 92)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier. A remote code execution vulnerability exists in the content sharing functionality because of a Buffer Overflow via crafted packets.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 5.24% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-05-13 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| polycom | group series |
| polycom | hdx |
| polycom | pano |
References
→ the Explorer · watch your stack · NVD