PT-2024-1828 · Zscaler · Zscaler Internet Access
Published
2024-01-31
·
Updated
2024-02-09
·
CVE-2023-28807
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Zscaler Internet Access (ZIA) (affected versions not specified)
Description
The issue is related to a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) in Zscaler Internet Access (ZIA), which enables attackers to evade network security controls by hiding their communications within legitimate traffic. This can be exploited to perform a man-in-the-middle attack.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zscaler Internet Access