6.4
CVSSv3

CVE-2025-43918

CVSSv4: NA | CVSSv3: 6.4 | CVSSv2: NA | VMScore: 740 | EPSS: 0.00011 | KEV: Not Included
Published: 19/04/2025 Updated: 21/04/2025

Vulnerability Summary

Domain Validation Bypass Leading to Unauthorized TLS Certificate Issuance in SSL.com

SSL.com prior to 2025-04-19, when domain validation method 3.2.2.4.14 is used, processes certificate requests such that a trusted TLS certificate may be issued for the domain name of a requester's email address, even when the requester does not otherwise establish administrative control of that domain.

Vulnerable Product Search on Vulmon Subscribe to Product

ssl.com ssl.com