Plantronics + Polycom. Now together as Poly Logo

ssh version on vxx500

Highlighted
Visitor

ssh version on vxx500

Because of security requirements for PCI and HIPAA we run network scans, using Nessus, on our internal network for compliance on these certifications.   Resently (September) our scans started showing a critical vulnerability on the VXX500 phones for Dropbear SSH being vulnerable to multiple exploits and a requirement of being at version 2016.74 or highter, the firmware uses SSH-2.0-dropbear_0.51.

I opened a ticket with support and it was closed with no comment other then to contact the vendor I purchased the phones from.   I am running the most current firmware on the phones and am now looking for a either a work around or a solution.   Any input would be appreciated.   Ideally I would like Polycom to update the firmware.

Message 1 of 4
3 REPLIES 3
Highlighted
Polycom Employee & Community Manager

Re: ssh version on vxx500

Hello ICchuck,

welcome to the Polycom Community.

It is always useful to include the currently used UC Software version as issues experienced or a question asked may already be addressed in a newer release.

This also allows yourself and others to check against current software release notes, Administrator Guides or FAQ post’s.

The above is also stated in the "Read First"

Therefore the Polycom VoIP FAQ contains this post here:

Question: How can I find out my SIP or UC Software Version of my Phone?
Resolution: Please check here

 

We are already aware of this so please keep an eye out on release notes stating VOIP-122152


Please ensure to provide some feedback if this reply has helped you so other users can profit from your experience.

Best Regards

Steffen Baier

Polycom Global Services

----------------

Notice: This community forum is not an official Poly support resource, thus responses from Poly employees, partners, and customers alike are best-effort in attempts to share learned knowledge. If you need immediate and/or official assistance please open a service ticket through your proper support channels.
Please also ensure you always check the VoIP , Video Endpoint , Skype for Business , PSTN or RPM FAQ's
Message 2 of 4
Highlighted
Visitor

Re: ssh version on vxx500

just to supply the missing information, our current software level on the VXX500 is  5.5.0.20556 

 

thanks for the response 

Message 3 of 4
Highlighted
Polycom Employee & Community Manager

Re: ssh version on vxx500

Hello ,

just as an FYI, UC Sofwtare 5.5.0 is not supported to be used with LYNC / Skype for business.

 

Please downgrade to UC Software 5.4.5

Please ensure to provide some feedback if this reply has helped you so other users can profit from your experience.

Best Regards

Steffen Baier

Polycom Global Services

----------------

Notice: This community forum is not an official Poly support resource, thus responses from Poly employees, partners, and customers alike are best-effort in attempts to share learned knowledge. If you need immediate and/or official assistance please open a service ticket through your proper support channels.
Please also ensure you always check the VoIP , Video Endpoint , Skype for Business , PSTN or RPM FAQ's
Message 4 of 4