CVE-2023-32803
Received Received - Intake

Incorrect Root CA Certificates in Amazon Linux 2 ca-certificates Package

Vulnerability report for CVE-2023-32803, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: MITRE

Description

The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
amazon ca-certificates to 2021.2.50-72 (exc)
amazon certifi 2022.12.07

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-669 The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2023-32803 is a security issue in the ca-certificates package for Amazon Linux. It involves an incomplete fix for CVE-2022-23491 where TrustCor root certificates were not properly removed from the root store. This allows attackers to perform man-in-the-middle attacks by exploiting these retained certificates.

Detection Guidance

To detect this vulnerability, check if your system has the ca-certificates package installed and verify its version. Run 'rpm -q ca-certificates' on Amazon Linux systems. If the package is outdated or contains TrustCor certificates, it may be vulnerable.

Impact Analysis

This vulnerability could allow attackers to intercept and manipulate encrypted communications by impersonating trusted entities. Systems using affected Amazon Linux versions may be vulnerable to unauthorized data access or modification if TrustCor certificates remain in the root store.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA. The issue involves improperly retained TrustCor root certificates in the ca-certificates package, which could enable man-in-the-middle attacks. Compliance with GDPR or HIPAA depends on data protection measures, not certificate trust stores.

Mitigation Strategies

Update the ca-certificates package immediately using 'yum update ca-certificates' or 'yum update --advisory ALAS2-2023-1957' for Amazon Linux 2. Ensure the package version is 2021.2.50-72 or later to remove TrustCor certificates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-32803. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart