CVE-2023-37920: Certifi

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.

Affected products

  • Certifi Certifi: from 2015.4.28, before 2023.7.22 (fixed in 2023.7.22)
  • Fedoraproject Fedora: version 38 only
  • Netapp Active Iq Unified Manager: affected versions not specified
  • Netapp Management Services For Element Software: affected versions not specified
  • Netapp Management Services For Netapp Hci: affected versions not specified
  • Netapp Ontap Mediator: affected versions not specified
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified
  • Netapp Solidfire & Hci Storage Node: affected versions not specified

Published 2023-07-25. Last modified 2026-06-17.