Traffic Bypass Vulnerability in Zscaler Client Connector for Windows
CVE-2025-54983

5.2MEDIUM

Key Information:

Vendor

Zscaler

Vendor
CVE Published:
12 November 2025

What is CVE-2025-54983?

A vulnerability in the Zscaler Client Connector for Windows exposes systems to potential security risks by allowing traffic to bypass established forwarding controls. In versions 4.6.0.216 and earlier, along with 4.7.0.47 and earlier, the health check port may not have been adequately closed under certain conditions, leading to unauthorized traffic access. This vulnerability can compromise network integrity and expose sensitive data if not addressed promptly.

Affected Version(s)

Zscaler Client Connector Windows 4.6 < 4.6.0.216

Zscaler Client Connector Windows 4.7 < 4.7.0.47

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

DTCC Team
.
CVE-2025-54983 : Traffic Bypass Vulnerability in Zscaler Client Connector for Windows