CVE-2023-37920
published 2023-07-25CVE-2023-37920: Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi…
PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.47%
37.5th percentile
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| certifi | certifi | >= 2015.4.28 < 2023.7.22 | 2023.7.22 |
| certifi | certifi | >= 2015.4.28 < 2023.7.22 | 2023.7.22 |
| certifi | python-certifi | — | — |
| certifi | python-certifi | >= 0 < 2023.7.22-1 | 2023.7.22-1 |
| certifi | python-certifi | >= 0 < 2023.7.22-1 | 2023.7.22-1 |
| debian | python-certifi | < python-certifi 2023.7.22-1 (forky) | python-certifi 2023.7.22-1 (forky) |
| fedoraproject | fedora | — | — |
| msrc | azl3_python-certifi_2023.05.07-1.cm2_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-certifi_2023.05.07-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_oracle9.8HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Install (Certifi) — CVE-2023-37920
vendor_oracle·2024-07-15·CVSS 9.8
CVE-2023-37920 [HIGH] Oracle Oracle Communications Risk Matrix: Install (Certifi) — CVE-2023-37920
Oracle Oracle Communications Risk Matrix: Install (Certifi) vulnerability
CVE: CVE-2023-37920
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Red Hat
python-certifi: Removal of e-Tugra root certificate
vendor_redhat·2023-07-25·CVSS 7.5
CVE-2023-37920 [HIGH] CWE-345 python-certifi: Removal of e-Tugra root certificate
python-certifi: Removal of e-Tugra root certificate
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
A flaw was found in the python-certifi package. This issue occurs when the e-Tugra root certificate in Certifi is removed, resulting in an unspecified error that has an unknown impact and attack vector.
Statement: While eTurgra certificates being marked as untrusted by Mozilla is significant from a trust and securit
Microsoft
Certifi's removal of e-Tugra root certificate
vendor_msrc·2023-07-11·CVSS 9.8
CVE-2023-37920 [HIGH] CWE-345 Certifi's removal of e-Tugra root certificate
Certifi's removal of e-Tugra root certificate
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.mic
Debian
CVE-2023-37920: python-certifi - Certifi is a curated collection of Root Certificates for validating the trustwor...
vendor_debian·2023·CVSS 7.5
CVE-2023-37920 [HIGH] CVE-2023-37920: python-certifi - Certifi is a curated collection of Root Certificates for validating the trustwor...
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2023.7.22-1)
sid: resolved (fixed in 2023.7.22-1)
trixie: resolved (fixed in 2023.7.22-1)
OSV
CVE-2023-37920: Certifi 2023
osv·2023-08-03
CVE-2023-37920 CVE-2023-37920: Certifi 2023
Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store. These are in the process of being removed from Mozilla's trust store. e-Tugra's root certificates are being removed pursuant to an investigation prompted by reporting of security issues in their systems.
GHSA
Removal of e-Tugra root certificate
ghsa·2023-07-25
CVE-2023-37920 [HIGH] CWE-345 Removal of e-Tugra root certificate
Removal of e-Tugra root certificate
Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store. These are in the process of being removed from Mozilla's trust store.
e-Tugra's root certificates are being removed pursuant to an investigation prompted by reporting of security issues in their systems. Conclusions of Mozilla's investigation can be found [here](https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1A).
OSV
Removal of e-Tugra root certificate
osv·2023-07-25
CVE-2023-37920 [HIGH] Removal of e-Tugra root certificate
Removal of e-Tugra root certificate
Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store. These are in the process of being removed from Mozilla's trust store.
e-Tugra's root certificates are being removed pursuant to an investigation prompted by reporting of security issues in their systems. Conclusions of Mozilla's investigation can be found [here](https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1A).
OSV
CVE-2023-37920: Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts
osv·2023-07-25·CVSS 9.8
CVE-2023-37920 [CRITICAL] CVE-2023-37920: Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
No detection rules found.
No public exploits indexed.
Qualys
Oracle Critical Patch Update, July 2024 Security Update Review
blogs_qualys·2024-07-17
Oracle Critical Patch Update, July 2024 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle released its third quarterly edition of Critical Patch Update, which contains patches for 386 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In the third quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 95, constituting about 24% of the total patches released. Oracle Financial Services Applications and Oracle Fusion Middleware foll
Qualys
Oracle Critical Patch Security Update: July 2024 Review | Qualys
blogs_qualys·2024-07-17
Oracle Critical Patch Security Update: July 2024 Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle released its third quarterly edition of Critical Patch Update, which contains patches for 386 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In the third quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 95, constituting about 24% of the total patches released. Oracle Financial Services Applications and Oracle Fusion Middlewa
Bugzilla
CVE-2023-37920 python-certifi: Removal of e-Tugra root certificate
bugzilla·2023-07-26·CVSS 9.8
CVE-2023-37920 [CRITICAL] CVE-2023-37920 python-certifi: Removal of e-Tugra root certificate
CVE-2023-37920 python-certifi: Removal of e-Tugra root certificate
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1A
https://github.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7
https://github.com/certifi/python-certifi/commit/8fb96ed81f71e7097ed11bc4d9b19afd7ea5c909
Discussion:
Created mingw-python-certifi tracking bug
https://github.com/certifi/python-certifi/commit/8fb96ed81f71e7097ed11bc4d9b19afd7ea5c909https://github.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1Ahttps://lists.fedoraproject.org/archives/list/[email protected]/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG/https://github.com/certifi/python-certifi/commit/8fb96ed81f71e7097ed11bc4d9b19afd7ea5c909https://github.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1Ahttps://lists.fedoraproject.org/archives/list/[email protected]/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG/https://security.netapp.com/advisory/ntap-20240912-0002/
2023-07-25
Published