« Volver al listado

CVE-2023-36535

Estado: ModificadaMedia (6.5)—

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-36535",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-36535",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-08T15:00:22.199594Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@zoom.us",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@zoom.us",
      "affectedData": [
        {
          "vendor": "Zoom Video Communications, Inc.",
          "product": "Zoom Clients",
          "versions": [
            {
              "status": "affected",
              "version": "before 5.14.10"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-08-08T18:15:14.207",
  "references": [
    {
      "url": "https://explore.zoom.us/en/trust/security/security-bulletin/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@zoom.us"
    },
    {
      "url": "https://explore.zoom.us/en/trust/security/security-bulletin/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@zoom.us",
      "description": [
        {
          "lang": "en",
          "value": "CWE-449"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access."
    },
    {
      "lang": "es",
      "value": "La aplicación del lado del cliente de la seguridad del lado del servidor en los clientes en Zoom anteriores a la versión 5.14.10 puede permitir que un usuario autenticado permita la divulgación de información a través del acceso a la red."
    }
  ],
  "lastModified": "2026-06-17T06:06:29.200",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zoom:rooms:*:*:*:*:*:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A529300E-4547-4D4D-B2EB-762C4F107CD8",
              "versionEndExcluding": "5.14.10"
            },
            {
              "criteria": "cpe:2.3:a:zoom:rooms:*:*:*:*:*:ipad_os:*:*",
              "vulnerable": true,
              "matchCriteriaId": "42FCEAAC-A453-4EDA-90A9-A82A23D8F685",
              "versionEndExcluding": "5.14.10"
            },
            {
              "criteria": "cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:*",
              "vulnerable": true,
              "matchCriteriaId": "666607A8-8F43-4B14-9CA7-D851376D05B5",
              "versionEndExcluding": "5.14.10"
            },
            {
              "criteria": "cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F8E8291-00C6-49CA-AB93-5E9FD0868959",
              "versionEndExcluding": "5.14.10"
            },
            {
              "criteria": "cpe:2.3:a:zoom:virtual_desktop_infrastructure:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1430CF6C-7A2B-4755-8AEC-95E706DA1F07",
              "versionEndExcluding": "5.14.10"
            },
            {
              "criteria": "cpe:2.3:a:zoom:zoom:*:*:*:*:*:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A66A1E5-9D2A-4533-B803-6C1B74C7AA5D",
              "versionEndExcluding": "5.14.10"
            },
            {
              "criteria": "cpe:2.3:a:zoom:zoom:*:*:*:*:*:iphone_os:*:*",
              "vulnerable": true,
              "matchCriteriaId": "516E7E40-A476-4277-8363-43FE4F748240",
              "versionEndExcluding": "5.14.10"
            },
            {
              "criteria": "cpe:2.3:a:zoom:zoom:*:*:*:*:*:linux:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3674A229-D066-4C97-93C5-E30824B54742",
              "versionEndExcluding": "5.14.10"
            },
            {
              "criteria": "cpe:2.3:a:zoom:zoom:*:*:*:*:*:macos:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6B3D7B50-B13B-45D3-AE2C-7EBB1DE30FA4",
              "versionEndExcluding": "5.14.10"
            },
            {
              "criteria": "cpe:2.3:a:zoom:zoom:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2DE0D4A-F97E-41D3-9906-427BEFFBDB8F",
              "versionEndExcluding": "5.14.10"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@zoom.us"
}