Poly Video - Sensitive Data Might Be Written to Log File
Summary
| CVE | CVE-2025-14432 |
|---|---|
| State | PUBLISHED |
| Assigner | hp |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-12-16 16:15:57 UTC |
| Updated | 2026-09-30 20:10:00 UTC |
| Description | In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is limited to Microsoft TAC and does not affect configuration changes made using the provisioning server or the device WebUI. |
Risk And Classification
Primary CVSS: v4.0 8.1 HIGH from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.004000000 probability, percentile 0.316510000 (date 2026-09-29)
Problem Types: CWE-532 | CWE-532 CWE-532: Insertion of Sensitive Information into Log File
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 8.1 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 8.1 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
| 3.1 | [email protected] | Primary | 4.9 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
HighUser Interaction
ActiveConfidentiality
HighIntegrity
NoneAvailability
NoneSub Conf.
HighSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Hp | Poly Eagleeye Cube | - | All | All | All |
| Hardware | Hp | Poly Eagleeye Iv | - | All | All | All |
| Hardware | Hp | Poly Studio A2 | - | All | All | All |
| Hardware | Hp | Poly Studio E60 | - | All | All | All |
| Hardware | Hp | Poly Studio E70 | - | All | All | All |
| Hardware | Hp | Poly Studio G62 | - | All | All | All |
| Hardware | Hp | Poly Studio G7500 | - | All | All | All |
| Hardware | Hp | Poly Studio Usb | - | All | All | All |
| Hardware | Hp | Poly Studio X30 | - | All | All | All |
| Hardware | Hp | Poly Studio X32 | - | All | All | All |
| Hardware | Hp | Poly Studio X50 | - | All | All | All |
| Hardware | Hp | Poly Studio X52 | - | All | All | All |
| Hardware | Hp | Poly Studio X70 | - | All | All | All |
| Hardware | Hp | Poly Studio X72 | - | All | All | All |
| Hardware | Hp | Poly Tc10 | - | All | All | All |
| Hardware | Hp | Poly Tc8 | - | All | All | All |
| Operating System | Hp | Poly Tcos | All | All | All | All |
| Operating System | Hp | Poly Videoos | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | HP Inc | Poly G7500 | affected <PolyOS 4.6.1-444242 custom | Not specified |
| CNA | HP Inc | Poly Studio G62 | affected <PolyOS 4.6.1-444242 custom | Not specified |
| CNA | HP Inc | Poly Studio X72 | affected <PolyOS 4.6.1-444242 custom | Not specified |
| CNA | HP Inc | Poly Studio X52 | affected <PolyOS 4.6.1-444242 custom | Not specified |
| CNA | HP Inc | Poly Studio X32 | affected <PolyOS 4.6.1-444242 custom | Not specified |
| CNA | HP Inc | Poly Studio X70 | affected <PolyOS 4.6.1-444242 custom | Not specified |
| CNA | HP Inc | Poly Studio X50 | affected <PolyOS 4.6.1-444242 custom | Not specified |
| CNA | HP Inc | Poly Studio X30 | affected <PolyOS 4.6.1-444242 custom | Not specified |
| CNA | HP Inc | Poly Studio E70 | affected <PolyOS 4.6.1-444242 custom | Not specified |
| CNA | HP Inc | Poly Studio E60 | affected <PolyOS 4.6.1-444242 custom | Not specified |
| CNA | HP Inc | Poly EagleEye Cube | affected <PolyOS 4.6.1-444242 custom | Not specified |
| CNA | HP Inc | Polycom EagleEye IV | affected <PolyOS 4.6.1-444242 custom | Not specified |
| CNA | HP Inc | Poly Studio A2 | affected <PolyOS 4.6.1-444242 custom | Not specified |
| CNA | HP Inc | Poly Studio USB | affected <PolyOS 4.6.1-444242 custom | Not specified |
| CNA | HP Inc | TC8 | affected <TCOS 6.6.1-7001859 custom | Not specified |
| CNA | HP Inc | TC10 | affected <TCOS 6.6.1-7001859 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| support.hp.com/us-en/document/ish_13612310-13612332-16/hpsbpy04080 | [email protected] | support.hp.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.