CVE-2023-41717: Medium severity zscaler vulnerability
Published Aug 31, 2023
·Updated
Inappropriate file type control in Zscaler Proxy versions 3.6.1.25 and prior allows local attackers to bypass file download/upload restrictions.
Affected Software
1 affected component
Zscaler Zscaler Proxy Windows<=3.6.1.25
Event History
Aug 31, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-41717?
CVE-2023-41717 is a vulnerability in Zscaler Proxy versions 3.6.1.25 and prior that allows local attackers to bypass file download/upload restrictions.
2
What is the severity of CVE-2023-41717?
CVE-2023-41717 has a severity rating of medium, with a CVSS score of 5.5.
3
How does CVE-2023-41717 affect Zscaler Proxy?
CVE-2023-41717 affects Zscaler Proxy versions 3.6.1.25 and prior.
4
How can local attackers exploit CVE-2023-41717?
Local attackers can exploit CVE-2023-41717 to bypass file download/upload restrictions.
5
Is there a fix available for CVE-2023-41717?
At the moment, there is no information available about a fix for CVE-2023-41717.