Lucene search

K
cvelistZoomCVELIST:CVE-2023-36533
HistoryAug 08, 2023 - 5:33 p.m.

CVE-2023-36533

2023-08-0817:33:47
CWE-400
Zoom
www.cve.org
zoom
sdks
denial of service
unauthenticated user
network access

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H

0.001 Low

EPSS

Percentile

20.5%

Uncontrolled resource consumption in Zoom SDKs before 5.14.7 may allow an unauthenticated user to enable a denial of service via network access.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Zoom SDK's",
    "vendor": "Zoom Video Communications, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "before 5.14.7"
      }
    ]
  }
]

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H

0.001 Low

EPSS

Percentile

20.5%

Related for CVELIST:CVE-2023-36533