CVE-2021-34414 describes a remote command injection vulnerability in the network proxy configuration page of several Zoom on-premise connector products, including Meeting, Recording, and Virtual Room Connectors, and the Virtual Room Connector Load Balancer. This flaw, rated High severity (CVSS 7.2), allows a web portal administrator to execute arbitrary commands due to insufficient input validation. While the attack requires administrator privileges, successful exploitation could lead to full compromise of the affected on-premise image. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.6.348.20201217CPE matchmatch criteria | cpe:2.3:a:zoom:meeting_connector:*:*:*:*:*:*:*:* | ||
< 3.8.42.20200905CPE matchmatch criteria | cpe:2.3:a:zoom:recording_connector:*:*:*:*:*:*:*:* | ||
< 4.4.6620.20201110CPE matchmatch criteria | cpe:2.3:a:zoom:virtual_room_connector:*:*:*:*:*:*:*:* | ||
< 2.5.5495.20210326CPE matchmatch criteria | cpe:2.3:a:zoom:virtual_room_connector_load_balancer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.