Lucene search

K
nvd[email protected]NVD:CVE-2021-34414
HistorySep 27, 2021 - 2:15 p.m.

CVE-2021-34414

2021-09-2714:15:08
CWE-20
web.nvd.nist.gov
7
zoom
network proxy
remote command injection

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

50.0%

The network proxy page on the web portal for the Zoom on-premise Meeting Connector Controller before version 4.6.348.20201217, Zoom on-premise Meeting Connector MMR before version 4.6.348.20201217, Zoom on-premise Recording Connector before version 3.8.42.20200905, Zoom on-premise Virtual Room Connector before version 4.4.6620.20201110, and Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5495.20210326 fails to validate input sent in requests to update the network proxy configuration, which could lead to remote command injection on the on-premise image by a web portal administrator.

Affected configurations

Nvd
Node
zoommeeting_connectorRange<4.6.348.20201217
OR
zoomrecording_connectorRange<3.8.42.20200905
OR
zoomvirtual_room_connectorRange<4.4.6620.20201110
OR
zoomvirtual_room_connector_load_balancerRange<2.5.5495.20210326
VendorProductVersionCPE
zoommeeting_connector*cpe:2.3:a:zoom:meeting_connector:*:*:*:*:*:*:*:*
zoomrecording_connector*cpe:2.3:a:zoom:recording_connector:*:*:*:*:*:*:*:*
zoomvirtual_room_connector*cpe:2.3:a:zoom:virtual_room_connector:*:*:*:*:*:*:*:*
zoomvirtual_room_connector_load_balancer*cpe:2.3:a:zoom:virtual_room_connector_load_balancer:*:*:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

50.0%

Related for NVD:CVE-2021-34414