PT-2023-7999 · Eset · Eset Mail Security For Microsoft Exchange Server+12

Published

2023-12-21

·

Updated

2024-02-20

·

CVE-2023-5594

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ESET NOD32 versions (affected versions not specified) ESET Internet Security versions (affected versions not specified) ESET Smart Security Premium versions (affected versions not specified) ESET Security Ultimate versions (affected versions not specified) ESET Endpoint Antivirus for Windows versions (affected versions not specified) ESET Endpoint Security for Windows versions (affected versions not specified) ESET Endpoint Antivirus for Linux versions (affected versions not specified) ESET Server Security for Windows Server versions (affected versions not specified) ESET Mail Security for Microsoft Exchange Server versions (affected versions not specified) ESET Mail Security for IBM Domino versions (affected versions not specified) ESET Security for Microsoft SharePoint Server versions (affected versions not specified) ESET File Security for Microsoft Azure versions (affected versions not specified) ESET Server Security for Linux versions (affected versions not specified)
Description The issue is related to improper validation of the server's certificate chain in the secure traffic scanning feature, which considers intermediate certificates signed using the MD5 or SHA1 algorithm as trusted. This could allow a remote attacker to bypass security protections, causing a browser to trust websites that should not be trusted. The vulnerability is caused by errors in the certificate authentication procedure. There have been no reported attacks exploiting this issue.
Recommendations For all affected ESET products, updates have been automatically rolled out since November 21, and no user action is required to install the patch. As a temporary workaround, consider disabling the secure traffic scanning feature until the update is applied. Restrict access to websites with certificates signed using outdated algorithms like MD5 or SHA1 to minimize the risk of exploitation. Avoid using the secure traffic scanning feature in sensitive environments until the patch is confirmed to be installed. At the moment, there is no additional information about other mitigation measures.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BDU:2023-09113
CVE-2023-5594

Affected Products

Eset Endpoint Antivirus For Linux
Eset Endpoint Antivirus For Windows
Eset Endpoint Security For Windows
Eset File Security For Microsoft Azure
Eset Internet Security
Eset Mail Security For Ibm Domino
Eset Mail Security For Microsoft Exchange Server
Eset Nod32 Antivirus
Eset Security Ultimate
Eset Security For Microsoft Sharepoint Server
Eset Server Security For Linux
Eset Server Security For Windows Server
Eset Smart Security Premium