CVE-2023-28802Improper Validation of Integrity Check Value in Client Connector

Severity
5.4MEDIUMNVD
CNA4.9
EPSS
0.1%
top 74.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 21

Description

An Improper Validation of Integrity Check Value in Zscaler Client Connector on Windows allows an authenticated user to disable ZIA/ZPA by interrupting the service restart from Zscaler Diagnostics. This issue affects Client Connector: before 4.2.0.149.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:LExploitability: 2.8 | Impact: 2.5

Affected Packages2 packages

CVEListV5zscaler/client_connector< 4.2.0.149
NVDzscaler/client_connector< 4.2.0.149

🔴Vulnerability Details

2
CVEList
Disable Zscaler using machine tunnel restart2023-11-21
GHSA
GHSA-67fh-hvmh-rhv8: An Improper Validation of Integrity Check Value in Zscaler Client Connector on Windows allows an authenticated user to disable ZIA/ZPA by interrupting2023-11-21
CVE-2023-28802 — Zscaler Client Connector vulnerability | cvebase