HIGH
SIP Service Providers – Possible Impersonation of Poly Voice Device
Published Mar 3, 2026
8.2
HIGHCVSS 4.0
EPSS 0.09%
Description
An embedded test key and certificate could be extracted from a Poly Voice device using specialized reverse engineering tools. This extracted certificate could be accepted by a SIP service provider if the service provider does not perform proper validation of the device certificate.
Affected products
-
Affected
- ≥ 0, < <PVOS 8.5.0
-
Affected
- ≥ 0, < <UCS 8.1.7.c
-
Affected
- ≥ 0, < <UCS 6.4.8
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hp
Published Mar 3, 2026
Updated Mar 3, 2026
Reserved Jan 8, 2026
Link CVE-2026-0754
CISA Vulnrichment
Updated Mar 3, 2026
Red Hat
No data
GitHub
No data