CVE-2023-28804: Linux ZCC allows unsigned updates, allowing elevated Code Execution
Published Oct 23, 2023
·Updated
An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing binaries.This issue affects Linux Client Connector: before 1.4.0.105
Affected Software
1 affected component
Zscaler Client Connector Linux<1.4.0.105
Event History
Oct 23, 2023
CVE Published
01:33 PM
Data Sourced
01:33 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-28804?
The severity of CVE-2023-28804 is high with a CVSS score of 8.2.
2
Which software is affected by CVE-2023-28804?
The Zscaler Client Connector on Linux versions before 1.4.0.105 is affected by CVE-2023-28804.
3
What is the vulnerability in CVE-2023-28804?
CVE-2023-28804 is an Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux that allows replacing binaries.
4
How can the vulnerability in CVE-2023-28804 be exploited?
The vulnerability in CVE-2023-28804 can be exploited by malicious actors to replace binaries.
5
Where can I find more information about CVE-2023-28804?
You can find more information about CVE-2023-28804 in the Zscaler Client Connector App Release Summary for 2023.