Home
CRITICAL: 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N 0.28.4
affected
v0.28.3
affected
Description
An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol authorization checks.
Problem types
CWE-287: Improper Authentication
Product status
v0.28.3
Credits
Stephen Kubik of the Cisco Advanced Security Initiatives Group (ASIG)
References
www.talosintelligence.com/...ability_reports/TALOS-2025-2242
talosintelligence.com/vulnerability_reports/TALOS-2025-2242
github.com/...icates/security/advisories/GHSA-h8cp-697h-8c8p
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.