// For flags

CVE-2021-34418

Pre-auth Null pointer crash in on-premise web console

Severity Score

5.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The login routine of the web console in the Zoom On-Premise Meeting Connector before version 4.6.239.20200613, Zoom On-Premise Meeting Connector MMR before version 4.6.239.20200613, Zoom On-Premise Recording Connector before version 3.8.42.20200905, Zoom On-Premise Virtual Room Connector before version 4.4.6344.20200612, and Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5492.20200616 fails to validate that a NULL byte was sent while authenticating. This could lead to a crash of the login service.

La rutina de inicio de sesión de la consola web en Zoom On-Premise Meeting Connector versiones anteriores a 4.6.239.20200613, Zoom On-Premise Meeting Connector MMR versiones anteriores a 4.6.239.20200613, Zoom On-Premise Recording Connector versiones anteriores a 3.8.42. 20200905, Zoom On-Premise Virtual Room Connector versiones anteriores a 4.4.6344.20200612 y Zoom On-Premise Virtual Room Connector Load Balancer versiones anteriores a 2.5.5492.20200616, no comprueban que se haya enviado un byte NULL mientras se autentican. Esto podría conllevar un fallo en el servicio de inicio de sesión

*Credits: Jeremy Brown
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-06-09 CVE Reserved
  • 2021-11-11 CVE Published
  • 2024-07-28 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-476: NULL Pointer Dereference
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Zoom
Search vendor "Zoom"
Zoom On-premise Meeting Connector Controller
Search vendor "Zoom" for product "Zoom On-premise Meeting Connector Controller"
< 4.6.239.20200613
Search vendor "Zoom" for product "Zoom On-premise Meeting Connector Controller" and version " < 4.6.239.20200613"
-
Affected
Zoom
Search vendor "Zoom"
Zoom On-premise Meeting Connector Mmr
Search vendor "Zoom" for product "Zoom On-premise Meeting Connector Mmr"
< 4.6.239.20200613
Search vendor "Zoom" for product "Zoom On-premise Meeting Connector Mmr" and version " < 4.6.239.20200613"
-
Affected
Zoom
Search vendor "Zoom"
Zoom On-premise Recording Connector
Search vendor "Zoom" for product "Zoom On-premise Recording Connector"
< 3.8.42.20200905
Search vendor "Zoom" for product "Zoom On-premise Recording Connector" and version " < 3.8.42.20200905"
-
Affected
Zoom
Search vendor "Zoom"
Zoom On-premise Virtual Room Connector
Search vendor "Zoom" for product "Zoom On-premise Virtual Room Connector"
< 4.4.6344.20200612
Search vendor "Zoom" for product "Zoom On-premise Virtual Room Connector" and version " < 4.4.6344.20200612"
-
Affected
Zoom
Search vendor "Zoom"
Zoom On-premise Virtual Room Connector Load Balancer
Search vendor "Zoom" for product "Zoom On-premise Virtual Room Connector Load Balancer"
< 2.5.5492.20200616
Search vendor "Zoom" for product "Zoom On-premise Virtual Room Connector Load Balancer" and version " < 2.5.5492.20200616"
-
Affected