CVE-2025-43918

SSL.com before 2025-04-19, when domain validation method 3.2.2.4.14 is used, processes certificate requests such that a trusted TLS certificate may be issued for the domain name of a requester's email address, even when the requester does not otherwise establish administrative control of that domain.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) SSL.com antes del 19/04/2025, cuando se utiliza el método de validación de dominio 3.2.2.4.14, procesa las solicitudes de certificados de manera tal que se pueda emitir un certificado TLS confiable para el nombre de dominio de la dirección de correo electrónico de un solicitante, incluso cuando el solicitante no establece de otro modo el control administrativo de ese dominio.

19 Apr 2025, 23:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.4
CWE CWE-348

19 Apr 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-19 22:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-43918

Mitre link : CVE-2025-43918

CVE.ORG link : CVE-2025-43918


JSON object : View

Products Affected

No product.

CWE
CWE-348

Use of Less Trusted Source