CVE Vulnerabilities

CVE-2023-28807

Improper Certificate Validation

Published: Jan 31, 2024 | Modified: Feb 09, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hellos Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traffic.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Secure_internet_and_saas_access Zscaler * 6.2r.290 (excluding)

Potential Mitigations

References