CVE-2023-28807

MEDIUM

Zscaler Internet Access < 6.2r.290 - Improper Certificate Validation via SNI Mismatch

Title source: llm
STIX 2.1

Description

In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traffic.

Scores

CVSS v3 5.1
EPSS 0.0034
EPSS Percentile 25.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (1)
zscaler/secure_internet_and_saas_access < 6.2r.290
Published Jan 31, 2024
Tracked Since Feb 18, 2026