Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-39689

24
FAUCET Score

CVE-2024-39689 addresses the removal of GLOBALTRUST root certificates from Certifi versions 2024.7.4 and later, due to unresolved compliance issues. This vulnerability, affecting Certifi and various NetApp products utilizing it, has a CVSS score of 7.5 (High), indicating a critical integrity risk where an unauthenticated attacker could compromise TLS host identity validation. While no active exploitation, public exploit code, or significant community discussion has been observed, the high FAUCET Risk Score of 89/100 underscores the potential for severe impact if exploited. Organizations are advised to update Certifi to mitigate the risk of trusting untrustworthy SSL certificates.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2021.5.30, < 2024.7.4CPE matchmatch criteria
cpe:2.3:a:certifi:certifi:*:*:*:*:*:python:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
10CPE matchmatch criteria
cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.05%
Probability of exploitation in next 30 days
EPSS Percentile
60.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0105 is in the 37th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

3cxpatch availablevia llm_extracted
Fixed in: 3.34.3
github_advisorypatch availablevia nvd_reference
View patch
mediatekpatch availablevia llm_extracted
Fixed in: 2.2.0
mediatekpatch availablevia llm_extracted
Fixed in: 4.7.0
mediatekpatch availablevia llm_extracted
Fixed in: 4.5.2
pippatch availablevia ghsa
Product: certifiFixed in: 2024.7.4

Vendor Advisories (7)

3cxllm-3cx-95fcc1a26c0643b1HIGH

Third-Party Package Updates in Splunk Connect for Syslog - April 2025

Apr 9, 2025
mediatekllm-mediatek-07f14aebcf69020aHIGH

Third-Party Package Updates in the Splunk Add-on for Cisco Meraki - October 2024

Oct 30, 2024
mediatekllm-mediatek-2749056fe1d0ff8fHIGH

Third-Party Package Updates in the Splunk Add-on for Google Cloud Platform - October 2024

Oct 30, 2024
mediatekllm-mediatek-83fe03d377f8e38eHIGH

Third-Party Package Updates in Splunk Add-on for Microsoft Office 365 - October 2024

Oct 17, 2024
microsoft2024-Jul/CVE-2024-39689Important

Certifi removes GLOBALTRUST root certificate

Jul 9, 2024
pipGHSA-248v-346w-9cwclow

Certifi removes GLOBALTRUST root certificate

Jul 5, 2024
redhatCVE-2024-39689Low

python-certifi: Remove root certificates from `GLOBALTRUST` from the root store

Jul 3, 2024

References

security.netapp.com / advisory/ntap-20241206-0001
Third Party Advisory
github.com / certifi/python-certifi/commit/bd8153872e9c6fc98f4023df9c2deaffea2fa463
Patch
github.com / certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc
Vendor Advisory
groups.google.com / a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI
Mailing List