7.5

CVE-2023-39217

Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to enable a denial of service via network access.

Data is provided by the National Vulnerability Database (NVD)
ZoomMeeting Software Development Kit SwPlatformandroid Version < 5.14.10
ZoomMeeting Software Development Kit SwPlatformiphone_os Version < 5.14.10
ZoomMeeting Software Development Kit SwPlatformlinux Version < 5.14.10
ZoomMeeting Software Development Kit SwPlatformmacos Version < 5.14.10
ZoomMeeting Software Development Kit SwPlatformwindows Version < 5.14.10
ZoomVideo Software Development Kit SwPlatformandroid Version < 5.14.10
ZoomVideo Software Development Kit SwPlatformiphone_os Version < 5.14.10
ZoomVideo Software Development Kit SwPlatformlinux Version < 5.14.10
ZoomVideo Software Development Kit SwPlatformmacos Version < 5.14.10
ZoomVideo Software Development Kit SwPlatformwindows Version < 5.14.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.17% 0.388
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
security@zoom.us 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.