Bypass of ZIA domain fronting detection module through evasion technique
Vulnerability Description
In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traffic.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-28807
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Citi Red Team
References
More from Zscaler
View All →Affected Vendor
Zscaler
View all reports →