CVE-2023-5594

EUVD-2023-57887
Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
ESETCNA
7.5 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
Affected Products (NVD)
VendorProductVersion
esetendpoint_antivirus
10.0 ≤
esetendpoint_antivirus
-
esetendpoint_security
-
esetfile_security
-
esetinternet_security
-
esetmail_security
-
esetmail_security
-
esetnod32_antivirus
-
esetsecurity
-
esetsecurity
-
esetserver_security
10.1 ≤
esetserver_security
-
esetsmart_security
-
𝑥
= Vulnerable software versions