In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hellos Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traffic.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Secure_internet_and_saas_access | Zscaler | * | 6.2r.290 (excluding) |