SSL.com before 2025-04-19, when domain validation method 3.2.2.4.14 is used, processes certificate requests such that a trusted TLS certificate may be issued for the domain name of a requester's email address, even when the requester does not otherwise establish administrative control of that domain.
References
Configurations
No configuration.
History
19 Apr 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.4 |
CWE | CWE-348 |
19 Apr 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-19 22:15
Updated : 2025-04-21 14:23
NVD link : CVE-2025-43918
Mitre link : CVE-2025-43918
CVE.ORG link : CVE-2025-43918
JSON object : View
Products Affected
No product.
CWE
CWE-348
Use of Less Trusted Source