CVE-2023-5594

Severity
8.6HIGH
EPSS
0.1%
top 71.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 21

Description

Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:NExploitability: 2.2 | Impact: 4.7

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-4mwg-64w4-5g5m: Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or S2023-12-21
CVEList
Improper following of a certificate's chain of trust in ESET security products2023-12-21
CVE-2023-5594 (HIGH CVSS 8.6) | Improper validation of the server’s | cvebase.io