8.6
CVE-2023-5594
- EPSS 0.1%
- Published 21.12.2023 12:15:08
- Last modified 21.11.2024 08:42:05
- Source security@eset.com
- Teams watchlist Login
- Open Login
Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.
Data is provided by the National Vulnerability Database (NVD)
Eset ≫ Endpoint Antivirus SwPlatformlinux Version >= 10.0
Eset ≫ Endpoint Antivirus Version- SwPlatformwindows
Eset ≫ Endpoint Security Version- SwPlatformwindows
Eset ≫ File Security Version- SwPlatformazure
Eset ≫ Internet Security Version-
Eset ≫ Mail Security Version- SwPlatformdomino
Eset ≫ Mail Security Version- SwPlatformexchange_server
Eset ≫ Nod32 Antivirus Version-
Eset ≫ Server Security SwPlatformlinux Version >= 10.1
Eset ≫ Server Security Version- SwPlatformwindows_server
Eset ≫ Smart Security Version- SwEditionpremium
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.1% | 0.293 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.6 | 3.9 | 4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
|
security@eset.com | 7.5 | 2.2 | 4.7 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.