V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2022-25243
CVE
Medium

"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard ce…

CVSS
6.5
Medium
EPSS
0.01
p41
Published
2022-01-01
Updated
2022-01-01
Description

"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.

Tags · CWE
CWE-285
CWE-295
CAPEC-1
CAPEC-5
CAPEC-13
CAPEC-17
CAPEC-39
CAPEC-45
CAPEC-51
CAPEC-59
CAPEC-60
CAPEC-76
CAPEC-77
CAPEC-87
CAPEC-104
CAPEC-127
CAPEC-402
CAPEC-459
CAPEC-475
CAPEC-647
CAPEC-668
Affected products
Vault 1.8.0–1.8.9Vault 1.9.0–1.9.4
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Timeline
2022-01-01
Published
2022-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: H
High (H)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.005 · p41
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-647 · CWE-285
└ via CAPEC-647 · CWE-285
└ via CAPEC-127 · CWE-285
└ via CAPEC-60 · CWE-285
└ via CAPEC-60 · CWE-285
└ via CAPEC-647 · CWE-285
└ via CAPEC-668 · CWE-285
└ via CAPEC-13 · CWE-285
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
vault*Tracked
Source databases
CVE