PT-2024-1828 · Zscaler · Zscaler Internet Access

Published

2024-01-31

·

Updated

2024-02-09

·

CVE-2023-28807

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Zscaler Internet Access (ZIA) (affected versions not specified)
Description The issue is related to a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) in Zscaler Internet Access (ZIA), which enables attackers to evade network security controls by hiding their communications within legitimate traffic. This can be exploited to perform a man-in-the-middle attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01573
CVE-2023-28807

Affected Products

Zscaler Internet Access