VendorsZoommeeting_connectorall versions
Vulnerabilities

Zoom Meeting Connector

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2022-28750
Zoom On-Premise Deployments: Stack Buffer Overflow in Meeting Connector
Published 2022-08-11 · Modified
9.8EPSS 0.020
CVE-2021-34416
The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-premise Meeting Connector MMR before version 4.6.360.20210325, Zoom on-premise Recording Connector before version 3.8.44.20210326, Zoom on-premise Virtual Room Connector before version 4.4.6752.20210326, and Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5495.20210326 fails to validate input sent in requests to update the network configuration, which could lead to remote command injection on the on-premise image by the web portal administrators.
Published 2021-09-27 · Modified
9.8EPSS 0.016
CVE-2021-34415
The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205 does not verify the cnt field sent in incoming network packets, which leads to exhaustion of resources and system crash.
Published 2021-09-27 · Modified
7.8EPSS 0.010
CVE-2021-34414
The network proxy page on the web portal for the Zoom on-premise Meeting Connector Controller before version 4.6.348.20201217, Zoom on-premise Meeting Connector MMR before version 4.6.348.20201217, Zoom on-premise Recording Connector before version 3.8.42.20200905, Zoom on-premise Virtual Room Connector before version 4.4.6620.20201110, and Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5495.20210326 fails to validate input sent in requests to update the network proxy configuration, which could lead to remote command injection on the on-premise image by a web portal administrator.
Published 2021-09-27 · Modified
7.2EPSS 0.015
CVE-2022-28754
Zoom On-Premise Deployments: Improper Access Control Vulnerability
Published 2022-08-11 · Modified
7.1EPSS 0.005
CVE-2022-28753
Zoom On-Premise Deployments: Improper Access Control Vulnerability
Published 2022-08-11 · Modified
7.1EPSS 0.005