CVE Vulnerabilities

CVE-2023-28807

Improper Certificate Validation

Published: Jan 31, 2024 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hellos Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traffic.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Secure_internet_and_saas_accessZscaler*6.2r.290 (excluding)

Potential Mitigations

References