8.6
CVE-2023-5594
- EPSS 0.38%
- Veröffentlicht 21.12.2023 12:15:08
- Zuletzt bearbeitet 21.11.2024 08:42:05
- Erkennungen
Improper following of a certificate's chain of trust in ESET security products
Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eset ≫ Endpoint Antivirus SwPlatform linux Version >= 10.0
Eset ≫ Endpoint Antivirus Version - SwPlatform windows
Eset ≫ Endpoint Security Version - SwPlatform windows
Eset ≫ File Security Version - SwPlatform azure
Eset ≫ Internet Security Version -
Eset ≫ Mail Security Version - SwPlatform domino
Eset ≫ Mail Security Version - SwPlatform exchange_server
Eset ≫ Nod32 Antivirus Version -
Eset ≫ Server Security SwPlatform linux Version >= 10.1
Eset ≫ Server Security Version - SwPlatform windows_server
Eset ≫ Smart Security Version - SwEdition premium
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.38% | 0.292 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.6 | 3.9 | 4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
|
| security@eset.com | 7.5 | 2.2 | 4.7 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
https://support.eset.com/en/ca8562-eset-customer-advisory-improper-following-of-a-certificates-chain-of-trust-in-eset-security-products-fixed