Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Endpoint Security

ESET Patches High-Severity Vulnerability in Secure Traffic Scanning Feature

ESET has patched CVE-2023-5594, a high-severity vulnerability that can cause a browser to trust websites that should not be trusted.

ESET has released patches for several of its endpoint and server security products to address a high-severity vulnerability that could have been exploited to cause web browsers to trust sites that should not be trusted.

The flaw, tracked as CVE-2023-5594, affected the SSL/TLS protocol scanning feature present in ESET products. It could have caused browsers to trust websites with certificates signed with outdated and insecure algorithms. 

“The vulnerability in the secure traffic scanning feature was caused by improper validation of the server’s certificate chain,” ESET explained in its advisory

It added, “An intermediate certificate signed using the MD5 or SHA1 algorithm was considered trusted, and thus the browser on a system with the ESET secure traffic scanning feature enabled could be caused to trust a site secured with such a certificate.”

The list of affected ESET products includes NOD32 Antivirus, Internet Security, Smart Security Premium, Security Ultimate, Endpoint Antivirus, Endpoint Security, Server Security, Mail Security, Security for Microsoft SharePoint Server, and File Security for Microsoft Azure.

Patches have been rolling out via automatic product updates since November 21 — no user interaction is required to install the fix. 

Advertisement. Scroll to continue reading.

The vulnerability was reported to ESET by an individual who wished to remain anonymous. The cybersecurity firm says it’s not aware of any attacks exploiting this vulnerability. 

Related: ESET Patches High-Severity Vulnerability in Windows Applications

Related: Serious Vulnerability Found in Imunify360 Web Server Security Product

Related: Trend Micro Patches Exploited Zero-Day Vulnerability in Endpoint Security Products

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Tracey Mustacchio has joined Everfox as Chief Marketing Officer.

Mark Carter has been appointed Chief Information Security Officer at Socure.

Spektrum Labs has named Mark Cravotta Chief Operating Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.