CVE Database
/

CVE-2021-34417

Back to search

CVE-2021-34417

Published: Nov 11, 2021

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.1

7.9

HIGH

Description

The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.20210703, Zoom On-Premise Meeting Connector MMR before version 4.6.365.20210703, Zoom On-Premise Recording Connector before version 3.8.45.20210703, Zoom On-Premise Virtual Room Connector before version 4.4.6868.20210703, and Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5496.20210703 fails to validate input sent in requests to set the network proxy password. This could lead to remote command injection by a web portal administrator.

VendorProductVersions

Zoom Video Communications Inc

Zoom On-Premise Meeting Connector Controller

affected
unspecified - < 4.6.365.20210703

Zoom Video Communications Inc

Zoom On-Premise Meeting Connector MMR

affected
unspecified - < 4.6.365.20210703

Zoom Video Communications Inc

Zoom On-Premise Recording Connector

affected
unspecified - < 3.8.45.20210703

Zoom Video Communications Inc

Zoom On-Premise Virtual Room Connector

affected
unspecified - < 4.4.6868.20210703

Zoom Video Communications Inc

Zoom On-Premise Virtual Room Connector Load Balancer

affected
unspecified - < 2.5.5496.20210703

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Attack Vector

Local

Attack Complexity

Low

Privileges Required

High

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now