CVE-2025-14432 Details
Description
In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is limited to Microsoft TAC and does not affect configuration changes made using the provisioning server or the device WebUI.
A vulnerability exists in certain HP Poly products that can lead to the unintentional logging of sensitive data. This issue arises when an administrator makes device configuration changes through the Microsoft Teams Admin Center (TAC). The logged data is only accessible to users with admin rights. Notably, this vulnerability is exclusive to Microsoft TAC and does not impact changes made via the provisioning server or the device's WebUI.
HP advises that device configuration changes be made using the provisioning server or the device WebUI, rather than the Microsoft Teams Admin Center, until the devices can be updated to the latest PolyOS version via Poly Lens. Instructions for using Poly Lens are available on the HP website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.hp.com/us-en/document/ish_13612310-13612332-16/hpsbpy04080 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hp poly videoos | < 4.6.1-444242 |
CPE
Remediation
| |
| hp poly eagleeye cube | All versions |
CPE
Remediation
| |
| hp poly eagleeye iv | All versions |
CPE
Remediation
| |
| hp poly studio a2 | All versions |
CPE
Remediation
| |
| hp poly studio e60 | All versions |
CPE
Remediation
| |
| hp poly studio e70 | All versions |
CPE
Remediation
| |
| hp poly studio g62 | All versions |
CPE
Remediation
| |
| hp poly studio g7500 | All versions |
CPE
Remediation
| |
| hp poly studio usb | All versions |
CPE
Remediation
| |
| hp poly studio x30 | All versions |
CPE
Remediation
| |
| hp poly studio x32 | All versions |
CPE
Remediation
| |
| hp poly studio x50 | All versions |
CPE
Remediation
| |
| hp poly studio x52 | All versions |
CPE
Remediation
| |
| hp poly studio x70 | All versions |
CPE
Remediation
| |
| hp poly studio x72 | All versions |
CPE
Remediation
| |
| hp poly tcos | < 6.6.1-7001859 |
CPE
Remediation
| |
| hp poly tc10 | All versions |
CPE
Remediation
| |
| hp poly tc8 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 18, 2025 | Initial Analysis | [email protected] |
| Dec 16, 2025 | New CVE Received | [email protected] |