CVE-2025-22918
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Feb 3, 2025
Updated: Feb 4, 2025
CWE ID 276
Summary
CVE-2025-22918 is a vulnerability affecting Polycom RealPresence Group 500 versions prior to 20. This issue stems from insecure permissions with automatically loaded cookies. Hackers can exploit this weakness to gain administrator functions, resulting in the unauthorized leakage of sensitive user information. This vulnerability poses a significant risk to organizations using the affected software for video conferencing and collaboration, emphasizing the need for timely patches and secure cookie handling practices.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- RealPresence Group 500