Vulnerability index

Browse CVEs

41 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-22569 An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspe… Client Connector 4.7.0.141 / 4.8.0.63+ Fix from $1,6002026-03-31 CRITICAL 9.8 CVE-2024-23483 An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connec… Client Connector 4.2+ Fix from $2,3002024-08-06 HIGH 7.8 CVE-2024-23458 While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a loc… Client Connector 4.2.0.190+ Fix from $1,9502024-08-06 HIGH 7.8 CVE-2024-23460 The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed… Client Connector 4.2+ Fix from $1,9502024-08-06 HIGH 7.5 CVE-2024-23456 Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tamp… Client Connector 4.2.0.190+ Fix from $1,9502024-08-06 MEDIUM 6.5 CVE-2023-28806 An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects… Client Connector 4.2.0.190+ Fix from $1,6002024-08-06 CRITICAL 9.8 CVE-2024-23459 An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Mac allows a system file to be overwri… Client Connector 3.7+ Fix from $2,3002024-05-02 HIGH 7.8 CVE-2023-41970 An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on Windows during the Repair App functionality may allow Lo… Client Connector 4.1.0.62+ Fix from $1,9502024-05-02 HIGH 7.8 CVE-2023-41971 An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Windows allows a system file to be ove… Client Connector 3.7+ Fix from $1,9502024-05-02 HIGH 7.5 CVE-2024-23462 An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS allows a denial of service of the Client Connector… Client Connector 3.4+ Fix from $1,9502024-05-02 MEDIUM 5.5 CVE-2024-23461 An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS during the upgrade process may allow a Local Execu… Client Connector 3.4+ Fix from $1,6002024-05-02 CRITICAL 9.8 CVE-2023-28798 An out-of-bounds write to heap in the pacparser library on Zscaler Client Connector on Mac may lead to arbitrary code execution. Client Connector 3.7+ Fix from $2,3002024-05-02 CRITICAL 9.8 CVE-2024-23480 A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to… Client Connector 4.2+ Fix from $2,3002024-05-01 HIGH 7.8 CVE-2024-23457 The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninstall password is enforced. Thi… Client Connector 4.2.0.209+ Fix from $1,9502024-05-01 HIGH 8.1 CVE-2024-23463 Anti-tampering protection of the Zscaler Client Connector can be bypassed under certain conditions when running the Repair App functionality. This af… Client Connector 4.2.1+ Fix from $1,9502024-04-30 HIGH 7.8 CVE-2024-23482 The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fixed Version: Mac ZApp 4.2.0.2… Client Connector 4.2.0.241+ Fix from $1,9502024-03-26 HIGH 7.8 CVE-2023-41972 In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: W… Client Connector 4.3.0.121+ Fix from $1,9502024-03-26 HIGH 7.8 CVE-2023-41973 ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName … Client Connector 4.3.0.121+ Fix from $1,9502024-03-26 HIGH 7.1 CVE-2023-41969 An arbitrary file deletion in ZSATrayManager where it protects the temporary encrypted ZApp issue reporting file from the unprivileged end user acces… Client Connector 4.3+ Fix from $1,9502024-03-26 HIGH 7.5 CVE-2023-28807 In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network s… Secure Internet And Saas Access 6.2r.290+ Fix from $1,9502024-01-31 MEDIUM 5.4 CVE-2023-28802 An Improper Validation of Integrity Check Value in Zscaler Client Connector on Windows allows an authenticated user to disable ZIA/ZPA by interruptin… Client Connector 4.2.0.149+ Fix from $1,6002023-11-21 MEDIUM 6.5 CVE-2023-28794 Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Privilege Abuse. This issue affects Zscaler Client Connector for Li… Client Connector 1.3.1.6+ Fix from $1,6002023-11-06 CRITICAL 9.8 CVE-2023-28805 An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue affects Client Connector: bef… Client Connector 1.4.0.105+ Fix from $2,3002023-10-23 HIGH 7.8 CVE-2021-26735 The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerability. A local adversary may be … Client Connector 3.6+ Fix from $1,9502023-10-23 HIGH 7.8 CVE-2021-26736 Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low … Client Connector 3.6+ Fix from $1,9502023-10-23 HIGH 7.8 CVE-2021-26738 Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable. A local adversary may be able to exe… Client Connector 3.7+ Fix from $1,9502023-10-23 HIGH 7.8 CVE-2023-28793 Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Clie… Client Connector 1.3.1.6+ Fix from $1,9502023-10-23 HIGH 7.8 CVE-2023-28795 Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process. This issue affects Zscaler C… Client Connector 1.3.1.6+ Fix from $1,9502023-10-23 HIGH 7.8 CVE-2023-28796 Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler… Client Connector 1.3.1.6+ Fix from $1,9502023-10-23 HIGH 7.3 CVE-2023-28797 Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk. A malicious user can replace… Client Connector 4.1+ Fix from $1,9502023-10-23