7.8
CVE-2024-23460
- EPSS 0.02%
- Published 06.08.2024 16:15:47
- Last modified 07.08.2024 21:29:01
- Source cve@zscaler.com
- Teams watchlist Login
- Open Login
The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.
Data is provided by the National Vulnerability Database (NVD)
Zscaler ≫ Client Connector SwPlatformmacos Version < 4.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.036 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
cve@zscaler.com | 6.4 | 1.2 | 5.2 |
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.