PT-2025-49107 · Step Ca · Step Ca

Stephen Kubik

·

Published

2025-12-03

·

Updated

2026-02-13

·

CVE-2025-44005

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Step CA (affected versions not specified)
Description A critical issue in Step CA allows for unauthenticated bypass, enabling the issuance of fraudulent certificates. This compromises trust in potentially millions of sites. The issue allows attackers to bypass security measures and generate unauthorized digital certificates, which could be used for malicious purposes such as phishing or man-in-the-middle attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Improper Authentication

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-KV78041
CVE-2025-44005
GHSA-H8CP-697H-8C8P
GO-2025-4180
SUSE-SU-2025:4395-1

Affected Products

Step Ca