CVE-2025-43918
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/04/2025
Last modified:
19/04/2025
Description
SSL.com before 2025-04-19, when domain validation method 3.2.2.4.14 is used, processes certificate requests such that a trusted TLS certificate may be issued for the domain name of a requester's email address, even when the requester does not otherwise establish administrative control of that domain.
Impact
Base Score 3.x
6.40
Severity 3.x
MEDIUM