GHSA-hwcc-4cv8-cf3h · Severity: medium · Ecosystem: nuget — Snowflake Connector .NET does not properly check the Certificate Revocation List (CRL)
The Snowflake .NET driver provides an interface to the Microsoft .NET open source software framework for developing applications. Snowflake recently received a report about a vulnerability in the Snowflake Connector .NET where the checks against the Certificate Revocation List (CRL) were not performed where the insecureMode flag was set to false, which is the default setting. The vulnerability affects versions between 2.0.25 and 2.1.4 (inclusive). Snowflake fixed the issue in version 2.1.5.
Conclusion & alert: CVE-2023-51662 is rated Moderate Risk (41.6/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.27%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-04 | 0.10% | 0.27% | +0.17% |
| 2 | 2026-03-01 | 0.27% | 0.10% | -0.17% |
| 3 | 2026-02-04 | — | 0.27% | — |
Full EPSS history (34 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.0 | 3.1 | MEDIUM |
|
0.5 | 5.5 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
1.6 | 5.9 | [email protected] |
GHSA-hwcc-4cv8-cf3h · Severity: medium · Ecosystem: nuget — Snowflake Connector .NET does not properly check the Certificate Revocation List (CRL)
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| snowflake | snowflake_connector | >= 2.0.25, < 2.1.5 | cpe:2.3:a:snowflake:snowflake_connector:*:*:*:*:*:.net:*:* |