CVE-2021-34415: High severity zoom meeting connector vulnerability
The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205 does not verify the cnt field sent in incoming network packets, which leads to exhaustion of resources and system crash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-34415?
CVE-2021-34415 is rated as a high severity vulnerability due to potential resource exhaustion and system crash.
How do I fix CVE-2021-34415?
To remediate CVE-2021-34415, upgrade to Zoom On-Premise Meeting Connector Controller version 4.6.358.20210205 or later.
What impact does CVE-2021-34415 have on systems?
CVE-2021-34415 can lead to a denial of service attack, resulting in resource exhaustion and inability to process incoming requests.
Which software versions are affected by CVE-2021-34415?
CVE-2021-34415 affects all versions of Zoom On-Premise Meeting Connector Controller prior to version 4.6.358.20210205.
Is there a workaround for CVE-2021-34415?
Currently, the recommended solution for CVE-2021-34415 is to upgrade the vulnerable software to a secure version.