Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Polycom

First CVE: Dec 31, 2002Active for: 24 yearsTotal CVEs: 39
39.5
VTI Score
Medium

Polycom's vulnerability footprint centers on unified communications and video conferencing infrastructure, including appliances and management platforms deployed across enterprise environments where accessibility and integration pressures often outweigh isolation. Its disclosures span a moderate product portfolio—including Unified Communications Software, RealPresence Resource Manager, and ViewStation endpoints—and demonstrate a meaningful share of serious-severity outcomes alongside an elevated tendency toward public exploit availability. The recurring weakness classes reflect the dual exposures of network-facing appliances and web management interfaces: sensitive-information leakage, cross-site scripting, OS command injection, and buffer-boundary violations appear consistently across the product line, creating overlapping attack surfaces in both remote-access and local-administrative contexts. Defenders should inventory video endpoints and management appliances systematically, prioritize patching for internet-reachable management interfaces, and treat Polycom advisories as broadly applicable within their communications infrastructure; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
39
Total CVEs
More Total CVEs than 98% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Polycom over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2002
23 years ago
Most Recent CVE
Oct 4, 2021
1,754 days ago

Products(107 total)

Top CVEs

Signals from CVEs in this vendor scope (39 CVEs).

39 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-6610HIGH
Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated by a ; (semicolon) to the ping c
Jan 28, 20208.841NOYES
CVE-2015-4683CRITICAL
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by leveraging use of session identifier
Sep 19, 20179.837NOYES
CVE-2018-15128CRITICAL
An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier. A remote code execution vulnerability exists in the content
May 13, 20199.832NONO
CVE-2012-6611CRITICAL
An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank
Feb 10, 20209.830NONO
CVE-2002-1906MEDIUM
The web server for Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (CPU consumption) by sending incomplete HTTP requests and leaving the connectio
Dec 31, 20025.030NOYES
CVE-2015-4681HIGH
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwords.
Sep 19, 20177.829NOYES
CVE-2021-41322HIGH
Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password reset process.
Oct 4, 20218.828NONO
CVE-2018-7565HIGH
CSRF exists on Polycom QDX 6000 devices.
Mar 7, 20188.827NONO
CVE-2015-4685HIGH
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a script in /var/polycom/cma/upgrade/scripts,
Sep 19, 20177.027NOYES
CVE-2015-4684MEDIUM
Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated users to read arbitrary files via a .. (d
Sep 19, 20176.527NOYES
View all 39 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products39 CVEs
41%
46%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (7.7%)
Network18 (46.2%)
Unknown12 (30.8%)
Physical1 (2.6%)
Adjacent Network5 (12.8%)
Attack Complexity
Low24 (61.5%)
High3 (7.7%)
Unknown12 (30.8%)
User Interaction
None24 (61.5%)
Unknown12 (30.8%)
Required3 (7.7%)
Privileges Required
Low9 (23.1%)
High3 (7.7%)
None15 (38.5%)
Unknown12 (30.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (39 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.6% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
17.9% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Polycom.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Polycom — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Polycom's Products

View all 1 CNAs →

Top CWEs