CVE-2023-28805: ZCC on Linux privilege escalation
Published Oct 23, 2023
·Updated
An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue affects Client Connector: before 1.4.0.105
Affected Software
1 affected component
Zscaler Client Connector Linux<1.4.0.105
Event History
Oct 23, 2023
CVE Published
01:33 PM
Data Sourced
01:33 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-28805.
2
What is the title of the vulnerability?
The title of the vulnerability is 'ZCC on Linux privilege escalation'.
3
What is the severity of CVE-2023-28805?
The severity of CVE-2023-28805 is critical with a CVSS score of 9.8.
4
Which software is affected by CVE-2023-28805?
Zscaler Client Connector on Linux version up to 1.4.0.105 is affected by CVE-2023-28805.
5
How can I fix the vulnerability?
To fix the vulnerability, update Zscaler Client Connector on Linux to version 1.4.0.105 or later.