CVE-2023-36539
30.06.2023, 03:15
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.Enginsight
Vendor | Product | Version |
---|---|---|
zoom | meetings | 5.15.0 |
zoom | meetings | 5.15.1 |
zoom | rooms | 5.15.0 |
zoom | rooms | 5.15.0 |
zoom | rooms | 5.15.0 |
zoom | video_software_development_kit | 1.8.0 |
zoom | zoom | 5.15.0 |
zoom | zoom | 5.15.0 |
zoom | zoom | 5.15.0 |
zoom | zoom | 5.15.1 |
zoom | poly_ccx_700_firmware | 5.15.0 |
zoom | poly_ccx_600_firmware | 5.15.0 |
zoom | yealink_vp59_firmware | 5.15.0 |
zoom | yealink_mp54_firmware | 5.15.0 |
zoom | yealink_mp56_firmware | 5.15.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-326 - Inadequate Encryption StrengthThe software stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.