PT-2023-21980 · Zscaler · Zscaler Client Connector

Published

2023-10-23

·

Updated

2023-10-27

·

CVE-2023-28804

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zscaler Client Connector versions prior to 1.4.0.105
Description An Improper Verification of Cryptographic Signature issue allows replacing binaries in Zscaler Client Connector on Linux.
Recommendations For versions prior to 1.4.0.105, update to version 1.4.0.105 or later to resolve the issue.

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2023-28804

Affected Products

Zscaler Client Connector