CVE-2023-36539
MEDIUMZoom Meetings and Poly CCX Firmware - Information Disclosure
Title source: llmDescription
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.
Scores
CVSS v3
5.3
EPSS
0.0019
EPSS Percentile
40.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-326
CWE-200
CWE-325
Status
published
Products (11)
zoom/meetings
5.15.0 (3 CPE variants)
zoom/meetings
5.15.1
zoom/poly_ccx_600_firmware
5.15.0
zoom/poly_ccx_700_firmware
5.15.0
zoom/rooms
5.15.0 (3 CPE variants)
zoom/video_software_development_kit
1.8.0
zoom/yealink_mp54_firmware
5.15.0
zoom/yealink_mp56_firmware
5.15.0
zoom/yealink_vp59_firmware
5.15.0
zoom/zoom
5.15.0 (5 CPE variants)
... and 1 more
Published
Jun 30, 2023
Tracked Since
Feb 18, 2026