Lucene search

K
cveZscalerCVE-2023-28807
HistoryJan 31, 2024 - 8:15 p.m.

CVE-2023-28807

2024-01-3120:15:44
CWE-295
Zscaler
web.nvd.nist.gov
16
zscaler
internet access
zia
sni
mismatch
vulnerability
nvd
cve-2023-28807

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

17.8%

In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello’s Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traffic.

Affected configurations

Nvd
Node
zscalersecure_internet_and_saas_accessRange<6.2r.290
VendorProductVersionCPE
zscalersecure_internet_and_saas_access*cpe:2.3:a:zscaler:secure_internet_and_saas_access:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "ZIA",
    "vendor": "Zscaler",
    "versions": [
      {
        "lessThan": "6.2r.290",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

17.8%

Related for CVE-2023-28807