Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23602 | An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowed an authentication abuse. |
| Link | Providers |
|---|---|
| https://help.zscaler.com/zia/about-identity-providers |
|
Tue, 05 Aug 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zscaler
Zscaler authentication Server |
|
| Vendors & Products |
Zscaler
Zscaler authentication Server |
Tue, 05 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 Aug 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowed an authentication abuse. | |
| Title | SAML 2.0 Public Key Validation Issue | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zscaler
Published:
Updated: 2026-02-26T17:49:58.538Z
Reserved: 2025-08-04T14:51:53.367Z
Link: CVE-2025-54982
Updated: 2025-08-05T15:59:06.512Z
Status : Deferred
Published: 2025-08-05T06:15:26.437
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-54982
No data.
OpenCVE Enrichment
Updated: 2025-08-05T21:23:03Z
EUVD