Poly Clariti Manager Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in Poly Clariti Manager versions prior to 10.12.2. This vulnerability allows a privileged user to submit arbitrary input, potentially leading to unauthorized command execution. HP has released a patch in the latest software update.

Impact

Exploitation of this vulnerability could result in remote code execution, allowing an attacker to execute arbitrary commands on the server where Poly Clariti Manager is running.

Remediation

Users are advised to update to version 10.12.2 or later. The latest builds can be obtained through the Poly Lens Management Console.

Added: Jul 22, 2025, 11:18 PM
Updated: Jul 22, 2025, 11:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.2
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.