CVE-2023-5594

HIGH

ESET Endpoint Antivirus and Server Security - Improper Certificate Validation in Secure Traffic Scanning

Title source: llm
STIX 2.1

Description

Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.

Scores

CVSS v3 7.5
EPSS 0.0038
EPSS Percentile 29.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N

Details

CWE
CWE-295
Status published
Products (11)
eset/endpoint_antivirus
eset/endpoint_antivirus 10.0
eset/endpoint_security
eset/file_security
eset/internet_security
eset/mail_security (2 CPE variants)
eset/nod32_antivirus
eset/security (2 CPE variants)
eset/server_security
eset/server_security 10.1
... and 1 more
Published Dec 21, 2023
Tracked Since Feb 18, 2026