PT-2023-21977 · Zscaler · Zscaler Admin Ui

Publicado

2023-08-31

·

Atualizado

2023-09-07

·

CVE-2023-28801

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zscaler Admin UI versions 6.2 before 6.2r
Description The issue is related to an improper verification of cryptographic signature in the SAML authentication of the Zscaler Admin UI, allowing a privilege escalation.
Recommendations For versions 6.2 before 6.2r, update to version 6.2r or later to resolve the issue. As a temporary workaround, consider restricting access to the SAML authentication feature in the Admin UI until a patch is applied.

Correção

Improper Verification of Cryptographic Signature

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-28801

Produtos afetados

Zscaler Admin Ui