An embedded test key and certificate could be extracted from a Poly Voice device using specialized reverse engineering tools. This extracted certificate could be accepted by a SIP service provider if the service provider does not perform proper validation of the device certificate.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 03 Mar 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An embedded test key and certificate could be extracted from a Poly Voice device using specialized reverse engineering tools. This extracted certificate could be accepted by a SIP service provider if the service provider does not perform proper validation of the device certificate. | |
| Title | SIP Service Providers – Possible Impersonation of Poly Voice Device | |
| Weaknesses | CWE-321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hp
Published:
Updated: 2026-03-03T00:48:06.776Z
Reserved: 2026-01-08T21:27:11.945Z
Link: CVE-2026-0754
No data.
Status : Received
Published: 2026-03-03T02:16:07.320
Modified: 2026-03-03T02:16:07.320
Link: CVE-2026-0754
No data.
OpenCVE Enrichment
No data.
Weaknesses