Polycom's vulnerability footprint centers on unified communications and video conferencing infrastructure, including appliances and management platforms deployed across enterprise environments where accessibility and integration pressures often outweigh isolation. Its disclosures span a moderate product portfolio—including Unified Communications Software, RealPresence Resource Manager, and ViewStation endpoints—and demonstrate a meaningful share of serious-severity outcomes alongside an elevated tendency toward public exploit availability. The recurring weakness classes reflect the dual exposures of network-facing appliances and web management interfaces: sensitive-information leakage, cross-site scripting, OS command injection, and buffer-boundary violations appear consistently across the product line, creating overlapping attack surfaces in both remote-access and local-administrative contexts. Defenders should inventory video endpoints and management appliances systematically, prioritize patching for internet-reachable management interfaces, and treat Polycom advisories as broadly applicable within their communications infrastructure; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Polycom over time
Signals from CVEs in this vendor scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6610HIGH Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated by a ; (semicolon) to the ping c | Jan 28, 2020 | 8.8 | 41 | NO | YES |
CVE-2015-4683CRITICAL Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by leveraging use of session identifier | Sep 19, 2017 | 9.8 | 37 | NO | YES |
CVE-2018-15128CRITICAL An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier. A remote code execution vulnerability exists in the content | May 13, 2019 | 9.8 | 32 | NO | NO |
CVE-2012-6611CRITICAL An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank | Feb 10, 2020 | 9.8 | 30 | NO | NO |
CVE-2002-1906MEDIUM The web server for Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (CPU consumption) by sending incomplete HTTP requests and leaving the connectio | Dec 31, 2002 | 5.0 | 30 | NO | YES |
CVE-2015-4681HIGH Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwords. | Sep 19, 2017 | 7.8 | 29 | NO | YES |
CVE-2021-41322HIGH Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password reset process. | Oct 4, 2021 | 8.8 | 28 | NO | NO |
CVE-2018-7565HIGH CSRF exists on Polycom QDX 6000 devices. | Mar 7, 2018 | 8.8 | 27 | NO | NO |
CVE-2015-4685HIGH Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a script in /var/polycom/cma/upgrade/scripts, | Sep 19, 2017 | 7.0 | 27 | NO | YES |
CVE-2015-4684MEDIUM Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated users to read arbitrary files via a .. (d | Sep 19, 2017 | 6.5 | 27 | NO | YES |
Signals from CVEs in this vendor scope (39 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Polycom.
Media articles that mention a CVE ID that affects a product developed by Polycom — matched by CVE ID, not by vendor name.