8.6

CVE-2023-5594

Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.

Data is provided by the National Vulnerability Database (NVD)
EsetEndpoint Antivirus SwPlatformlinux Version >= 10.0
EsetEndpoint Antivirus Version- SwPlatformwindows
EsetEndpoint Security Version- SwPlatformwindows
EsetFile Security Version- SwPlatformazure
EsetInternet Security Version-
EsetMail Security Version- SwPlatformdomino
EsetMail Security Version- SwPlatformexchange_server
EsetNod32 Antivirus Version-
EsetSecurity Version- SwPlatformsharepoint_server
EsetSecurity Version- SwEditionultimate
EsetServer Security SwPlatformlinux Version >= 10.1
EsetServer Security Version- SwPlatformwindows_server
EsetSmart Security Version- SwEditionpremium
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.1% 0.293
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
security@eset.com 7.5 2.2 4.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.