CVE-2023-5594: Improper following of a certificate's chain of trust in ESET security products
Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5594?
CVE-2023-5594 has been classified as a medium severity vulnerability due to improper validation of the server's certificate chain.
How do I fix CVE-2023-5594?
To fix CVE-2023-5594, ensure you update your ESET security products to the latest version where the vulnerability is patched.
Which ESET products are affected by CVE-2023-5594?
CVE-2023-5594 affects multiple ESET products, including ESET Endpoint Antivirus for Linux, ESET Endpoint Security for Windows, and ESET NOD32 Antivirus.
What type of attack does CVE-2023-5594 allow?
CVE-2023-5594 could allow an attacker to exploit the flaw to perform man-in-the-middle attacks by misusing intermediate certificates.
When was CVE-2023-5594 disclosed?
CVE-2023-5594 was disclosed in October 2023 as part of ESET's security advisory to address the vulnerability.