HIGH · 7.5

CVE-2023-5594

Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.

Vulnerability Description

Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
EsetEndpoint Antivirus>= 10.0
EsetEndpoint Security-
EsetFile Security-
EsetInternet Security-
EsetMail Security-
EsetNod32 Antivirus-
EsetSecurity-
EsetServer Security>= 10.1
EsetSmart Security-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-5594?

CVE-2023-5594 is a vulnerability with a CVSS score of 7.5 (HIGH). Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.

How severe is CVE-2023-5594?

CVE-2023-5594 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-5594?

Check the references section above for vendor advisories and patch information. Affected products include: Eset Endpoint Antivirus, Eset Endpoint Security, Eset File Security, Eset Internet Security, Eset Mail Security.