Junglewise Threat Intelligence

CVE-2026-2891: HP Poly Voice IP devices resource consumption in SIP processing

CVE-2026-2891 · Severity: info · CVSS 8.2 · Published 2026-07-01

Executive brief

Poly CCX, Trio, and Edge E desk phones and conference devices are vulnerable to a denial-of-service attack. If these devices connect to a malicious or compromised communications server, they can be rendered completely inoperable by malformed data. This could disrupt business communications and require manual intervention to restore service.

Technical details

This vulnerability is classified as uncontrolled resource consumption (CWE-400) within the SIP processing stack of Poly Voice IP devices. An attacker controlling a malicious SIP server can send specially crafted, malformed data to connected CCX, Trio, or Edge E devices. Successful exploitation results in a complete loss of availability, rendering the hardware inoperable. The attack is network-based and requires no user interaction, though it assumes the device is configured to communicate with the attacker-controlled server. HP has released firmware updates (CCX/Trio 9.5.0 and Edge E 8.6.0) to mitigate this issue.

Affected products

  • HP Poly CCX Before 9.5.0
  • HP Poly Trio C60 Before 9.5.0
  • HP Poly Edge E Before 8.6.0

Timeline

  • 2026-07-01: advisory
  • 2026-07-01: disclosed

References