CVE-2025-54983: Health check port on ZCC allows tunnel bypass
A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under specific circumstances was not released after use, allowed traffic to potentially bypass ZCC forwarding controls.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54983?
CVE-2025-54983 is considered a medium severity vulnerability due to the potential for traffic to bypass Zcc forwarding controls.
How do I fix CVE-2025-54983?
To mitigate CVE-2025-54983, upgrade Zscaler Client Connector to version 4.6.0.216 or later for 4.6.x, and 4.7.0.47 or later for 4.7.x.
Which versions of Zscaler Client Connector are affected by CVE-2025-54983?
CVE-2025-54983 affects Zscaler Client Connector versions 4.6.0.215 and earlier, as well as versions 4.7.0.46 and earlier.
What specific issue does CVE-2025-54983 involve?
CVE-2025-54983 involves a health check port not being released after use, allowing traffic to bypass Zscaler Client Connector's forwarding controls.
Is CVE-2025-54983 fixed in the latest Zscaler Client Connector version?
Yes, CVE-2025-54983 is fixed in the latest versions of Zscaler Client Connector beyond 4.6.0.216 and 4.7.0.47.