Vulnerability Description
The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205 does not verify the cnt field sent in incoming network packets, which leads to exhaustion of resources and system crash.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zoom | Meeting Connector | < 4.6.358.20210205 |
Related Weaknesses (CWE)
References
- https://explore.zoom.us/en/trust/security/security-bulletin/Vendor Advisory
- https://explore.zoom.us/en/trust/security/security-bulletin/Vendor Advisory
FAQ
What is CVE-2021-34415?
CVE-2021-34415 is a vulnerability with a CVSS score of 7.5 (HIGH). The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205 does not verify the cnt field sent in incoming network packets, which leads to exhaustio...
How severe is CVE-2021-34415?
CVE-2021-34415 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-34415?
Check the references section above for vendor advisories and patch information. Affected products include: Zoom Meeting Connector.