CVE-2023-28801: Improper SAML signature verification
Published Aug 31, 2023
·Updated
An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privilege Escalation.This issue affects Admin UI: from 6.2 before 6.2r.
Affected Software
1 affected component
Zscaler Zscaler Internet Access Admin Portal>=6.2<6.2r
Event History
Aug 31, 2023
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-28801?
CVE-2023-28801 is a vulnerability that allows privilege escalation due to an improper verification of cryptographic signature in the SAML authentication of the Zscaler Admin UI.
2
What is the severity of CVE-2023-28801?
CVE-2023-28801 has a severity rating of 9.8, which is classified as critical.
3
Which version of the Zscaler Admin UI is affected by CVE-2023-28801?
CVE-2023-28801 affects Zscaler Admin UI versions from 6.2 before 6.2r.
4
How does CVE-2023-28801 allow privilege escalation?
CVE-2023-28801 allows privilege escalation through an improper verification of cryptographic signature in the SAML authentication process of the Zscaler Admin UI.
5
How can I fix CVE-2023-28801?
To fix CVE-2023-28801, upgrade the Zscaler Admin UI to version 6.2r or newer.