CVE-2020-10659

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
18/03/2020
Last modified:
24/03/2020

Description

Entrust Entelligence Security Provider (ESP) before 10.0.60 on Windows mishandles errors during SSL Certificate Validation, leading to situations where (for example) a user continues to interact with a web site that has an invalid certificate chain.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:entrustdatacard:entelligence_security_provider:*:*:*:*:*:*:*:* 10.0.60 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*