7.5

CVE-2023-36539

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zoom ≫ Meetings Version 5.15.0 SwPlatform android
Zoom ≫ Meetings Version 5.15.0 SwPlatform iphone_os
Zoom ≫ Meetings Version 5.15.0 SwPlatform macos
Zoom ≫ Meetings Version 5.15.1 SwPlatform windows
Zoom ≫ Rooms Version 5.15.0 SwPlatform ipad_os
Zoom ≫ Rooms Version 5.15.0 SwPlatform macos
Zoom ≫ Rooms Version 5.15.0 SwPlatform windows
Zoom ≫ Zoom Version 5.15.0 SwPlatform android
Zoom ≫ Zoom Version 5.15.0 SwPlatform iphone_os
Zoom ≫ Zoom Version 5.15.0 SwPlatform linux
Zoom ≫ Zoom Version 5.15.0 SwPlatform macos
Zoom ≫ Zoom Version 5.15.0 SwPlatform windows
Zoom ≫ Zoom Version 5.15.1 SwPlatform windows
Zoom ≫ Poly Ccx 700 Firmware Version 5.15.0
   Zoom ≫ Poly Ccx 700 Version -
Zoom ≫ Poly Ccx 600 Firmware Version 5.15.0
   Zoom ≫ Poly Ccx 600 Version -
Zoom ≫ Yealink Vp59 Firmware Version 5.15.0
   Zoom ≫ Yealink Vp59 Version -
Zoom ≫ Yealink Mp54 Firmware Version 5.15.0
   Zoom ≫ Yealink Mp54 Version -
Zoom ≫ Yealink Mp56 Firmware Version 5.15.0
   Zoom ≫ Yealink Mp56 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.408
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
security@zoom.us 5.3 1.6 3.6
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-325 Missing Cryptographic Step

The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.

CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

https://explore.zoom.us/en/trust/security/security-bulletin/
Vendor Advisory