CVE Feed

    Dashboard / CVE / CVE-2022-23491

    CVE-2022-23491

    Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found in the linked google group discussion.

    Published:Dec 7, 2022
    Last Modified:Apr 23, 2025
    EPS:Dec 7, 2022
    EPSS Score:0.00041
    CVSS Score:6.8

    Affected Products

    Vendor
    Certifi
    Product
    Certifi
    Vendor
    Netapp
    Product
    E-series Performance Analyzer
    Vendor
    Netapp
    Product
    Management Services For Element Software
    Vendor
    Netapp
    Product
    Management Services For Netapp Hci
    Vendor
    Redhat
    Product
    Ansible Automation Platform
    Vendor
    Redhat
    Product
    Ceph Storage

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High