Security Advisory

CVE-2025-43918

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-04-19 00:00:00
Last updated 2025-04-21 14:19:27
Assigner mitre
State PUBLISHED

Description

SSL.com before 2025-04-19, when domain validation method 3.2.2.4.14 is used, processes certificate requests such that a trusted TLS certificate may be issued for the domain name of a requesters email address, even when the requester does not otherwise establish administrative control of that domain.