CVE-2025-44005
EUVD-2025-20101217.12.2025, 16:16
An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol authorization checks.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| smallstep | step-ca | 0.28.4 | CNA |
| smallstep | step-ca | 0.28.3 | CNA |
Common Weakness Enumeration