7.5

CVE-2023-36539

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

Data is provided by the National Vulnerability Database (NVD)
ZoomMeetings Version5.15.0 SwPlatformandroid
ZoomMeetings Version5.15.0 SwPlatformiphone_os
ZoomMeetings Version5.15.0 SwPlatformmacos
ZoomMeetings Version5.15.1 SwPlatformwindows
ZoomRooms Version5.15.0 SwPlatformipad_os
ZoomRooms Version5.15.0 SwPlatformmacos
ZoomRooms Version5.15.0 SwPlatformwindows
ZoomZoom Version5.15.0 SwPlatformandroid
ZoomZoom Version5.15.0 SwPlatformiphone_os
ZoomZoom Version5.15.0 SwPlatformlinux
ZoomZoom Version5.15.0 SwPlatformmacos
ZoomZoom Version5.15.0 SwPlatformwindows
ZoomZoom Version5.15.1 SwPlatformwindows
ZoomPoly Ccx 700 Firmware Version5.15.0
   ZoomPoly Ccx 700 Version-
ZoomPoly Ccx 600 Firmware Version5.15.0
   ZoomPoly Ccx 600 Version-
ZoomYealink Vp59 Firmware Version5.15.0
   ZoomYealink Vp59 Version-
ZoomYealink Mp54 Firmware Version5.15.0
   ZoomYealink Mp54 Version-
ZoomYealink Mp56 Firmware Version5.15.0
   ZoomYealink Mp56 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.18% 0.405
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
security@zoom.us 5.3 1.6 3.6
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-325 Missing Cryptographic Step

The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.

CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.