CVE-2024-23463

HIGH

Zscaler Client Connector <4.2.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

Anti-tampering protection of the Zscaler Client Connector can be bypassed under certain conditions when running the Repair App functionality. This affects Zscaler Client Connector on Windows prior to 4.2.1

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0037
EPSS Percentile 28.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-367
Status published
Products (1)
zscaler/client_connector < 4.2.1
Published Apr 30, 2024
Tracked Since Feb 18, 2026