---
id: CVE-2025-14432
title: >-
  In limited scenarios, sensitive data might be written to the log file if an
  admin uses Microsoft Teams Admin Center (TAC) to make device configuration
  changes
summary: >-
  In limited scenarios, sensitive data might be written to the log file if an
  admin uses Microsoft Teams Admin Center (TAC) to make device configuration
  changes. The affected log file is visible only to users with admin
  credentials. This i…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-532
vendor: hp
product: poly_videoos
affected:
  - poly_videoos < 4.6.1-444242
  - poly_tcos < 6.6.1-7001859
patched:
  - poly_videoos 4.6.1-444242
  - poly_tcos 6.6.1-7001859
published: '2025-12-16'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T20:10:00.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14432'
references:
  - url: 'https://support.hp.com/us-en/document/ish_13612310-13612332-16/hpsbpy04080'
    label: hp-security-alert@hp.com
tags:
  - nvd
epss: 0.004
epssPercentile: 0.31753
ingestedAt: '2026-09-30T20:23:19.454Z'
---

## Overview

In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is limited to Microsoft TAC and does not affect configuration changes made using the provisioning server or the device WebUI.

## Affected

- `poly_videoos < 4.6.1-444242`
- `poly_tcos < 6.6.1-7001859`

## Remediation

Upgrade past the affected range:

- `poly_videoos 4.6.1-444242`
- `poly_tcos 6.6.1-7001859`
