CVE Vulnerabilities

CVE-2023-5594

Improper Certificate Validation

Published: Dec 21, 2023 | Modified: Jan 04, 2024
CVSS 3.x
8.6
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Endpoint_antivirus Eset 10.0 (including) *
Endpoint_antivirus Eset - (including) - (including)
Endpoint_security Eset - (including) - (including)
File_security Eset - (including) - (including)
Internet_security Eset - (including) - (including)
Mail_security Eset - (including) - (including)
Nod32_antivirus Eset - (including) - (including)
Security Eset - (including) - (including)
Server_security Eset 10.1 (including) *
Server_security Eset - (including) - (including)
Smart_security Eset - (including) - (including)

Potential Mitigations

References