Vulnerability Description
In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traffic.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zscaler | Secure Internet And Saas Access | < 6.2r.290 |
Related Weaknesses (CWE)
References
- https://help.zscaler.com/zia/configuring-advanced-settings#dns-optimizationProduct
- https://help.zscaler.com/zia/configuring-advanced-settings#domain-frontingProduct
- https://help.zscaler.com/zia/configuring-advanced-settings#dns-optimizationProduct
- https://help.zscaler.com/zia/configuring-advanced-settings#domain-frontingProduct
FAQ
What is CVE-2023-28807?
CVE-2023-28807 is a vulnerability with a CVSS score of 5.1 (MEDIUM). In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications wit...
How severe is CVE-2023-28807?
CVE-2023-28807 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-28807?
Check the references section above for vendor advisories and patch information. Affected products include: Zscaler Secure Internet And Saas Access.