Lucene search

K
cveZoomCVE-2022-28761
HistoryOct 14, 2022 - 3:15 p.m.

CVE-2022-28761

2022-10-1415:15:16
CWE-284
Zoom
web.nvd.nist.gov
24
zoom
on-premise
meeting connector
mmr
cve-2022-28761
access control
vulnerability
nvd

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

29.7%

Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability. As a result, a malicious actor in a meeting or webinar they are authorized to join could prevent participants from receiving audio and video causing meeting disruptions.

Affected configurations

Nvd
Node
zoomzoom_on-premise_meeting_connector_mmrRange<4.8.20220916.131
VendorProductVersionCPE
zoomzoom_on-premise_meeting_connector_mmr*cpe:2.3:a:zoom:zoom_on-premise_meeting_connector_mmr:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Zoom Video Communications Inc",
    "product": "Zoom On-Premise Meeting Connector MMR",
    "versions": [
      {
        "version": "unspecified",
        "lessThan": "4.8.20220916.131",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

29.7%

Related for CVE-2022-28761