Vulnerability Description
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zoom | Meetings | 5.15.0 |
| Zoom | Rooms | 5.15.0 |
| Zoom | Video Software Development Kit | 1.8.0 |
| Zoom | Zoom | 5.15.0 |
| Zoom | Poly Ccx 700 Firmware | 5.15.0 |
| Zoom | Poly Ccx 700 | - |
| Zoom | Poly Ccx 600 Firmware | 5.15.0 |
| Zoom | Poly Ccx 600 | - |
| Zoom | Yealink Vp59 Firmware | 5.15.0 |
| Zoom | Yealink Vp59 | - |
| Zoom | Yealink Mp54 Firmware | 5.15.0 |
| Zoom | Yealink Mp54 | - |
| Zoom | Yealink Mp56 Firmware | 5.15.0 |
| Zoom | Yealink Mp56 | - |
Related Weaknesses (CWE)
References
- https://explore.zoom.us/en/trust/security/security-bulletin/Vendor Advisory
- https://explore.zoom.us/en/trust/security/security-bulletin/Vendor Advisory
FAQ
What is CVE-2023-36539?
CVE-2023-36539 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.
How severe is CVE-2023-36539?
CVE-2023-36539 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-36539?
Check the references section above for vendor advisories and patch information. Affected products include: Zoom Meetings, Zoom Rooms, Zoom Video Software Development Kit, Zoom Zoom, Zoom Poly Ccx 700 Firmware.