PT-2022-6879 · Zscaler · Zscaler Proxy

Federella

·

Published

2022-08-31

·

Updated

2023-09-07

·

CVE-2023-41717

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Zscaler Proxy versions 3.6.1.25 and prior
Description The issue is related to inappropriate file type control, which can be exploited by local attackers to bypass file download and upload restrictions. This can potentially allow an attacker to elevate their privileges by sending specially crafted requests, thus circumventing security limitations.
Recommendations For Zscaler Proxy versions 3.6.1.25 and prior, consider restricting access to the proxy server until a patch is available. As a temporary workaround, limit the types of files that can be uploaded or downloaded to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-05312
CVE-2023-41717

Affected Products

Zscaler Proxy