Vulnerability Description
Entrust Entelligence Security Provider (ESP) before 10.0.60 on Windows mishandles errors during SSL Certificate Validation, leading to situations where (for example) a user continues to interact with a web site that has an invalid certificate chain.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Entrustdatacard | Entelligence Security Provider | < 10.0.60 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://github.com/etherpacket/CVD-Applications/blob/master/EDC%20Security%20BulBroken Link
- https://github.com/etherpacket/CVD-Applications/blob/master/eespwin_10_10060_reaBroken Link
- https://github.com/etherpacket/CVD-Applications/blob/master/EDC%20Security%20BulBroken Link
- https://github.com/etherpacket/CVD-Applications/blob/master/eespwin_10_10060_reaBroken Link
FAQ
What is CVE-2020-10659?
CVE-2020-10659 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Entrust Entelligence Security Provider (ESP) before 10.0.60 on Windows mishandles errors during SSL Certificate Validation, leading to situations where (for example) a user continues to interact with ...
How severe is CVE-2020-10659?
CVE-2020-10659 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10659?
Check the references section above for vendor advisories and patch information. Affected products include: Entrustdatacard Entelligence Security Provider, Microsoft Windows.