5.3
CVE-2021-34418
- EPSS 0.18%
- Published 11.11.2021 23:15:09
- Last modified 21.11.2024 06:10:21
- Source security@zoom.us
- Teams watchlist Login
- Open Login
The login routine of the web console in the Zoom On-Premise Meeting Connector before version 4.6.239.20200613, Zoom On-Premise Meeting Connector MMR before version 4.6.239.20200613, Zoom On-Premise Recording Connector before version 3.8.42.20200905, Zoom On-Premise Virtual Room Connector before version 4.4.6344.20200612, and Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5492.20200616 fails to validate that a NULL byte was sent while authenticating. This could lead to a crash of the login service.
Data is provided by the National Vulnerability Database (NVD)
Zoom ≫ Zoom On-premise Meeting Connector Controller Version < 4.6.239.20200613
Zoom ≫ Zoom On-premise Meeting Connector Mmr Version < 4.6.239.20200613
Zoom ≫ Zoom On-premise Recording Connector Version < 3.8.42.20200905
Zoom ≫ Zoom On-premise Virtual Room Connector Version < 4.4.6344.20200612
Zoom ≫ Zoom On-premise Virtual Room Connector Load Balancer Version < 2.5.5492.20200616
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.18% | 0.371 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
security@zoom.us | 4 | 2.5 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.