CVE Vulnerabilities

CVE-2023-36539

Inadequate Encryption Strength

Published: Jun 30, 2023 | Modified: Jul 10, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

Name Vendor Start Version End Version
Meetings Zoom 5.15.0 (including) 5.15.0 (including)
Meetings Zoom 5.15.1 (including) 5.15.1 (including)
Rooms Zoom 5.15.0 (including) 5.15.0 (including)
Video_software_development_kit Zoom 1.8.0 (including) 1.8.0 (including)
Zoom Zoom 5.15.0 (including) 5.15.0 (including)
Zoom Zoom 5.15.1 (including) 5.15.1 (including)

Potential Mitigations

References