CVE-2023-37920

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
GitHub_MCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
VendorProductVersion
certificertifi
2015.4.28 ≤
𝑥
< 2023.7.22
netappactive_iq_unified_manager
-
netappactive_iq_unified_manager
-
netappmanagement_services_for_element_software
-
netappmanagement_services_for_netapp_hci
-
netappontap_mediator
-
netappontap_select_deploy_administration_utility
-
netappsolidfire_\&_hci_storage_node
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python-certifi
bullseye
unimportant
bookworm
unimportant
sid
2024.8.30+dfsg-1
fixed
trixie
2024.8.30+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-certifi
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
ignored
focal
ignored
bionic
ignored
xenial
ignored
trusty
ignored
python-pip
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
ignored
focal
ignored
bionic
ignored
xenial
ignored
trusty
ignored