Executive brief
A critical vulnerability exists in Poly Voice communication devices running on Linux. If the Interactive Connectivity Establishment (ICE) feature is enabled, a remote attacker could potentially take full control of the device. This could lead to unauthorized access to voice communications, service disruptions, or use of the device as a foothold within the corporate network.
Technical details
A stack-based buffer overflow (CWE-121) exists in the implementation of Interactive Connectivity Establishment (ICE) within Poly Voice products running on Linux. The vulnerability is reachable over the network without authentication, though it requires the ICE feature to be enabled by an administrator. An attacker can exploit this flaw to achieve remote code execution (RCE) with high impact on confidentiality, integrity, and availability. HP has assigned a CVSS 4.0 score of 9.2, reflecting the critical nature of the potential exploit.
Affected products
- HP (Poly) Poly Voice products (Linux)
Timeline
- 2026-06-01: advisory: Initial disclosure by HP and NVD publication