CVE-2023-36539
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.
Affected (19)
Configuration A
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.15.0 |
| Running on/with | Platform Versions |
|---|---|
Zoom Poly Ccx 700 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.15.0 |
| Running on/with | Platform Versions |
|---|---|
Zoom Poly Ccx 600 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.15.0 |
| Running on/with | Platform Versions |
|---|---|
Zoom Yealink Vp59 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.15.0 |
| Running on/with | Platform Versions |
|---|---|
Zoom Yealink Mp54 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.15.0 |
| Running on/with | Platform Versions |
|---|---|
Zoom Yealink Mp56 | All versions |
Related CWEs
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-325
Missing Cryptographic Step
The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.
CWE-326
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.