CVE-2023-28803: Traffic being bypassed by ZCC by configuring synthetic IP range as local network
Published Oct 23, 2023
·Updated
An authentication bypass by spoofing of a device with a synthetic IP address is possible in Zscaler Client Connector on Windows, allowing a functionality bypass. This issue affects Client Connector: before 3.9.
Affected Software
1 affected component
Zscaler Client Connector Windows<3.9
Event History
Oct 23, 2023
CVE Published
01:32 PM
Data Sourced
01:32 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-28803?
CVE-2023-28803 is an authentication bypass vulnerability in Zscaler Client Connector on Windows.
2
How does CVE-2023-28803 impact Zscaler Client Connector?
CVE-2023-28803 allows an attacker to bypass authentication by spoofing a device with a synthetic IP address in Zscaler Client Connector on Windows.
3
What is the severity of CVE-2023-28803?
The severity of CVE-2023-28803 is medium, with a CVSS score of 6.5.
4
Which version of Zscaler Client Connector is affected by CVE-2023-28803?
CVE-2023-28803 affects versions of Zscaler Client Connector before 3.9.
5
How can I fix CVE-2023-28803 vulnerability in Zscaler Client Connector?
To fix the CVE-2023-28803 vulnerability, it is recommended to update Zscaler Client Connector to version 3.9 or later.