CVE-2023-28793Code Injection in Client Connector

Severity
7.8HIGHNVD
EPSS
0.0%
top 87.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 23

Description

Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5zscaler/client_connector< 1.3.1.6

🔴Vulnerability Details

2
CVEList
Heap Based Buffer Overflow in Library2023-10-23
GHSA
GHSA-g99m-655w-j95w: Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection2023-10-23
CVE-2023-28793 — Code Injection in Client Connector | cvebase