CVE-2023-28807: Zscaler Secure Internet And Saas Access
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traffic.
Affected products
- Zscaler Secure Internet And Saas Access: before 6.2r.290 (fixed in 6.2r.290)
Published 2024-01-31. Last modified 2026-06-17.