CVE-2023-36539

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zoom:meetings:5.15.0:*:*:*:*:android:*:*
cpe:2.3:a:zoom:meetings:5.15.0:*:*:*:*:iphone_os:*:*
cpe:2.3:a:zoom:meetings:5.15.0:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:meetings:5.15.1:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:rooms:5.15.0:*:*:*:*:ipad_os:*:*
cpe:2.3:a:zoom:rooms:5.15.0:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:rooms:5.15.0:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:video_software_development_kit:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:zoom:zoom:5.15.0:*:*:*:*:android:*:*
cpe:2.3:a:zoom:zoom:5.15.0:*:*:*:*:iphone_os:*:*
cpe:2.3:a:zoom:zoom:5.15.0:*:*:*:*:linux:*:*
cpe:2.3:a:zoom:zoom:5.15.0:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:zoom:5.15.0:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:zoom:5.15.1:*:*:*:*:windows:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:zoom:poly_ccx_700_firmware:5.15.0:*:*:*:*:*:*:*
cpe:2.3:h:zoom:poly_ccx_700:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:zoom:poly_ccx_600_firmware:5.15.0:*:*:*:*:*:*:*
cpe:2.3:h:zoom:poly_ccx_600:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:zoom:yealink_vp59_firmware:5.15.0:*:*:*:*:*:*:*
cpe:2.3:h:zoom:yealink_vp59:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:zoom:yealink_mp54_firmware:5.15.0:*:*:*:*:*:*:*
cpe:2.3:h:zoom:yealink_mp54:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:zoom:yealink_mp56_firmware:5.15.0:*:*:*:*:*:*:*
cpe:2.3:h:zoom:yealink_mp56:-:*:*:*:*:*:*:*

History

10 Jul 2023, 13:29

Type Values Removed Values Added
CPE cpe:2.3:a:zoom:rooms:5.15.0:*:*:*:*:ipad_os:*:*
cpe:2.3:h:zoom:yealink_mp56:-:*:*:*:*:*:*:*
cpe:2.3:a:zoom:zoom:5.15.1:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:meetings:5.15.0:*:*:*:*:iphone_os:*:*
cpe:2.3:a:zoom:zoom:5.15.0:*:*:*:*:iphone_os:*:*
cpe:2.3:o:zoom:yealink_mp54_firmware:5.15.0:*:*:*:*:*:*:*
cpe:2.3:a:zoom:zoom:5.15.0:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:meetings:5.15.0:*:*:*:*:android:*:*
cpe:2.3:o:zoom:poly_ccx_700_firmware:5.15.0:*:*:*:*:*:*:*
cpe:2.3:a:zoom:video_software_development_kit:1.8.0:*:*:*:*:*:*:*
cpe:2.3:h:zoom:yealink_vp59:-:*:*:*:*:*:*:*
cpe:2.3:a:zoom:meetings:5.15.0:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:meetings:5.15.1:*:*:*:*:windows:*:*
cpe:2.3:h:zoom:yealink_mp54:-:*:*:*:*:*:*:*
cpe:2.3:a:zoom:zoom:5.15.0:*:*:*:*:android:*:*
cpe:2.3:a:zoom:rooms:5.15.0:*:*:*:*:windows:*:*
cpe:2.3:a:zoom:rooms:5.15.0:*:*:*:*:macos:*:*
cpe:2.3:h:zoom:poly_ccx_700:-:*:*:*:*:*:*:*
cpe:2.3:h:zoom:poly_ccx_600:-:*:*:*:*:*:*:*
cpe:2.3:o:zoom:poly_ccx_600_firmware:5.15.0:*:*:*:*:*:*:*
cpe:2.3:a:zoom:zoom:5.15.0:*:*:*:*:linux:*:*
cpe:2.3:o:zoom:yealink_mp56_firmware:5.15.0:*:*:*:*:*:*:*
cpe:2.3:a:zoom:zoom:5.15.0:*:*:*:*:windows:*:*
cpe:2.3:o:zoom:yealink_vp59_firmware:5.15.0:*:*:*:*:*:*:*
CWE CWE-326
References (MISC) https://explore.zoom.us/en/trust/security/security-bulletin/ - (MISC) https://explore.zoom.us/en/trust/security/security-bulletin/ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

30 Jun 2023, 12:59

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-30 03:15

Updated : 2024-02-04 23:37


NVD link : CVE-2023-36539

Mitre link : CVE-2023-36539

CVE.ORG link : CVE-2023-36539


JSON object : View

Products Affected

zoom

  • rooms
  • poly_ccx_700_firmware
  • zoom
  • yealink_mp54
  • yealink_mp56
  • yealink_mp54_firmware
  • yealink_mp56_firmware
  • poly_ccx_600
  • yealink_vp59
  • yealink_vp59_firmware
  • poly_ccx_600_firmware
  • poly_ccx_700
  • meetings
  • video_software_development_kit
CWE
CWE-326

Inadequate Encryption Strength