CVE Database
/

CVE-2021-34418

Back to search

CVE-2021-34418

Published: Nov 11, 2021

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.1

4.0

MEDIUM

Description

The login routine of the web console in the Zoom On-Premise Meeting Connector before version 4.6.239.20200613, Zoom On-Premise Meeting Connector MMR before version 4.6.239.20200613, Zoom On-Premise Recording Connector before version 3.8.42.20200905, Zoom On-Premise Virtual Room Connector before version 4.4.6344.20200612, and Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5492.20200616 fails to validate that a NULL byte was sent while authenticating. This could lead to a crash of the login service.

VendorProductVersions

Zoom Video Communications Inc

Zoom On-Premise Meeting Connector

affected
unspecified - < 4.6.239.20200613

Zoom Video Communications Inc

Zoom On-Premise Meeting Connector MMR

affected
unspecified - < 4.6.239.20200613

Zoom Video Communications Inc

Zoom On-Premise Recording Connector

affected
unspecified - < 3.8.42.20200905

Zoom Video Communications Inc

Zoom On-Premise Virtual Room Connector

affected
unspecified - < 4.4.6344.20200612

Zoom Video Communications Inc

Zoom On-Premise Virtual Room Connector Load Balancer

affected
unspecified - < 2.5.5492.20200616

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector

Local

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now