PT-2025-49107 · Step Ca · Step Ca
Stephen Kubik
·
Published
2025-12-03
·
Updated
2026-02-13
·
CVE-2025-44005
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Step CA (affected versions not specified)
Description
A critical issue in Step CA allows for unauthenticated bypass, enabling the issuance of fraudulent certificates. This compromises trust in potentially millions of sites. The issue allows attackers to bypass security measures and generate unauthorized digital certificates, which could be used for malicious purposes such as phishing or man-in-the-middle attacks.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Step Ca