CVE-2023-41972: Revert password check incorrect type validation
Published Mar 26, 2024
·Updated
In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: Win ZApp 4.3.0.121 and later.
Affected Software
2 affected components
Win ZApp Win ZApp<4.3.0.121
Zscaler Client Connector Windows<4.3.0.121
Event History
Mar 26, 2024
CVE Published
via MITRE·02:16 PM
Data Sourced
via MITRE·02:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-41972?
CVE-2023-41972 has a moderate severity level due to the potential for unauthorized password operations.
2
How do I fix CVE-2023-41972?
To fix CVE-2023-41972, upgrade to Win ZApp version 4.3.0.121 or later.
3
What is the impact of CVE-2023-41972?
The impact of CVE-2023-41972 includes possible unauthorized access through inadequate password validation in the Revert Password feature.
4
Is there a workaround for CVE-2023-41972?
There is no recommended workaround for CVE-2023-41972; upgrading to the fixed version is the best approach.
5
When was CVE-2023-41972 disclosed?
CVE-2023-41972 was disclosed on September 1, 2023.