CVE-2023-49646
13.12.2023, 23:15
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.Enginsight
Vendor | Product | Version |
---|---|---|
zoom | meeting_software_development_kit | 𝑥 < 5.16.5 |
zoom | video_software_development_kit | 𝑥 < 5.16.5 |
zoom | virtual_desktop_infrastructure | 𝑥 < 5.14.14 |
zoom | virtual_desktop_infrastructure | 5.15.0 ≤ 𝑥 < 5.15.12 |
zoom | zoom | 𝑥 < 5.16.5 |
zoom | zoom | 𝑥 < 5.16.5 |
zoom | zoom | 𝑥 < 5.16.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-347 - Improper Verification of Cryptographic SignatureThe software does not verify, or incorrectly verifies, the cryptographic signature for data.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.