MEDIUM · 5.3

CVE-2023-36539

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

Vulnerability Description

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
ZoomMeetings5.15.0
ZoomRooms5.15.0
ZoomVideo Software Development Kit1.8.0
ZoomZoom5.15.0
ZoomPoly Ccx 700 Firmware5.15.0
ZoomPoly Ccx 700-
ZoomPoly Ccx 600 Firmware5.15.0
ZoomPoly Ccx 600-
ZoomYealink Vp59 Firmware5.15.0
ZoomYealink Vp59-
ZoomYealink Mp54 Firmware5.15.0
ZoomYealink Mp54-
ZoomYealink Mp56 Firmware5.15.0
ZoomYealink Mp56-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-36539?

CVE-2023-36539 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

How severe is CVE-2023-36539?

CVE-2023-36539 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-36539?

Check the references section above for vendor advisories and patch information. Affected products include: Zoom Meetings, Zoom Rooms, Zoom Video Software Development Kit, Zoom Zoom, Zoom Poly Ccx 700 Firmware.