CVE-2022-23491 addresses the removal of "TrustCor" root certificates from the Certifi root store (version 2022.12.07 and later) due to an investigation into TrustCor's ownership operating a spyware business. This impacts various Certifi and NetApp products that rely on this root store for TLS host identity verification. The vulnerability is rated High (CVSS 7.5) with a network attack vector and low complexity, potentially leading to high integrity impact by allowing malicious actors to impersonate trusted TLS hosts. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2017.11.5, < 2022.12.7CPE matchmatch criteria | cpe:2.3:a:certifi:certifi:*:*:*:*:*:python:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:management_services_for_netapp_hci:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in NetWitness Logs and Packets App - April 2025
Apr 9, 2025August 2023 Third Party Package Updates in Splunk Enterprise
Aug 30, 2023June Third Party Package Updates in Splunk Cloud
Jun 1, 2023Certifi removing TrustCor root certificate
Dec 7, 2022python-certifi: untrusted root certificates
Dec 7, 2022