CVE-2020-10659: Entrustdatacard Entelligence Security Provider

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Entrust Entelligence Security Provider (ESP) before 10.0.60 on Windows mishandles errors during SSL Certificate Validation, leading to situations where (for example) a user continues to interact with a web site that has an invalid certificate chain.

Affected products

  • Entrustdatacard Entelligence Security Provider: before 10.0.60 (fixed in 10.0.60)

Published 2020-03-18. Last modified 2026-06-17.