ZeroHour

CVE-2023-37920

CVSS 3.1
9.8 critical
EPSS
<1%p45
Published
()
Modified
Description

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.

Vendors
certififedoraprojectnetapp
Products
certifi, fedora, active iq unified manager, management services for element software, management services for netapp hci, ontap mediator, ontap select deploy administration utility, solidfire \& hci storage node
Weakness
CWE-345
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.