{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-54983","assignerOrgId":"73c6f63b-efac-410d-a0a9-569700f85a04","state":"PUBLISHED","assignerShortName":"Zscaler","dateReserved":"2025-08-04T14:51:53.367Z","datePublished":"2025-11-12T03:07:39.531Z","dateUpdated":"2025-11-12T18:18:36.813Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["Windows"],"product":"Zscaler Client Connector","vendor":"Zscaler","versions":[{"lessThan":"4.6.0.216","status":"affected","version":"4.6","versionType":"custom"},{"lessThan":"4.7.0.47","status":"affected","version":"4.7","versionType":"custom"}]}],"credits":[{"lang":"en","type":"other","value":"DTCC Team"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"A health check port on Zscaler Client Connector on Windows, versions 4.6 &lt;  4.6.0.216 and 4.7 &lt; 4.7.0.47, which under specific circumstances was not released after use, allowed traffic to potentially bypass ZCC forwarding controls.\n\n<br>"}],"value":"A health check port on Zscaler Client Connector on Windows, versions 4.6 <  4.6.0.216 and 4.7 < 4.7.0.47, which under specific circumstances was not released after use, allowed traffic to potentially bypass ZCC forwarding controls."}],"impacts":[{"capecId":"CAPEC-554","descriptions":[{"lang":"en","value":"CAPEC-554 Functionality Bypass"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":5.2,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-772","description":"CWE-772 Missing Release of Resource after Effective Lifetime","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"73c6f63b-efac-410d-a0a9-569700f85a04","shortName":"Zscaler","dateUpdated":"2025-11-12T03:07:39.531Z"},"references":[{"url":"https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2025"}],"source":{"discovery":"UNKNOWN"},"title":"Health check port on ZCC allows tunnel bypass","x_generator":{"engine":"Vulnogram 0.5.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-11-12T18:18:25.758917Z","id":"CVE-2025-54983","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-11-12T18:18:36.813Z"}}]}}