PT-2021-20523 · Zoom · Zoom On-Premise Meeting Connector Mmr+3
Egor Dimitrenko
·
Published
2021-09-27
·
Updated
2021-11-10
·
CVE-2021-34416
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Zoom on-premise Meeting Connector versions prior to 4.6.360.20210325
Zoom on-premise Meeting Connector MMR versions prior to 4.6.360.20210325
Zoom on-premise Recording Connector versions prior to 3.8.44.20210326
Zoom on-premise Virtual Room Connector versions prior to 4.4.6752.20210326
Zoom on-premise Virtual Room Connector Load Balancer versions prior to 2.5.5495.20210326
Description:
The network address administrative settings web portal for the Zoom on-premise products fails to validate input sent in requests to update the network configuration, which could lead to remote command injection on the on-premise image by the web portal administrators.
Recommendations:
For Zoom on-premise Meeting Connector versions prior to 4.6.360.20210325, update to version 4.6.360.20210325 or later.
For Zoom on-premise Meeting Connector MMR versions prior to 4.6.360.20210325, update to version 4.6.360.20210325 or later.
For Zoom on-premise Recording Connector versions prior to 3.8.44.20210326, update to version 3.8.44.20210326 or later.
For Zoom on-premise Virtual Room Connector versions prior to 4.4.6752.20210326, update to version 4.4.6752.20210326 or later.
For Zoom on-premise Virtual Room Connector Load Balancer versions prior to 2.5.5495.20210326, update to version 2.5.5495.20210326 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoom On-Premise Meeting Connector Mmr
Zoom On-Premise Recording Connector
Zoom On-Premise Virtual Room Connector
Zoom On-Premise Virtual Room Connector Load Balancer