Impact
A file type attribution issue exists in Zscaler Internet Access File Type Control evaluation rules that may allow improper evaluation of File Type Control policies in rare circumstances. The flaw is an input validation weakness that could enable an attacker to trick the system into misclassifying file types, potentially bypassing restrictions and permitting the transmission of files that are normally blocked. Because the vulnerability is rooted in improper input validation (CWE‑20), the primary impact is a policy bypass that may facilitate the delivery of malicious or unintended content.
Affected Systems
This issue affects the Zscaler Internet Access product, specifically the File Type Control component. No specific version information is provided, so all current releases that implement the described evaluation rules are potentially impacted unless a patch has been applied after the documented release.
Risk and Exploitability
The CVSS score of 4.4 indicates a low severity threat. The EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation is not known. Based on the description, it is inferred that the vulnerability requires specific conditions to trigger a bypass, and no public exploitation has been reported. Overall, the risk is low, but the potential to undermine policy enforcement warrants monitoring for abnormal file type handling events.
OpenCVE Enrichment