Medium severity5.1NVD Advisory· Published Jan 31, 2024· Updated Jun 17, 2026
CVE-2023-28807
CVE-2023-28807
Description
In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traffic.
Affected products
3- cpe:2.3:a:zscaler:secure_internet_and_saas_access:*:*:*:*:*:*:*:*Range: <6.2r.290
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.