6.5
CVE-2024-39822
- EPSS 0.51%
- Veröffentlicht 14.08.2024 17:15:15
- Zuletzt bearbeitet 04.09.2024 21:28:37
- Erkennungen
Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers - Sensitive Information Exposure
Sensitive information exposure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct an information disclosure via network access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zoom ≫ Meeting Software Development Kit SwPlatform android Version < 6.0.12
Zoom ≫ Meeting Software Development Kit SwPlatform iphone_os Version < 6.0.12
Zoom ≫ Rooms Controller SwPlatform android Version < 6.1.0
Zoom ≫ Rooms Controller SwPlatform linux Version < 6.1.0
Zoom ≫ Rooms Controller SwPlatform macos Version < 6.1.0
Zoom ≫ Rooms Controller SwPlatform windows Version < 6.1.0
Zoom ≫ Workplace Desktop SwPlatform linux Version < 6.0.12
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.51% | 0.396 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| security@zoom.us | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://www.zoom.com/en/trust/security-bulletin/zsb-24029