CVE-2025-66406 - CERT CVE
ID CVE-2025-66406
Sažetak Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, there is an improper authorization check for SSH certificate revocation. This affects deployments configured with the SSHPOP provisioner. This vulnerability is fixed in 0.29.0.
Reference
CVSS
Base: 5.0
Impact: 4.2
Exploitability:0.7
Pristup
VektorSloženostAutentikacija
NETWORK HIGH HIGH
Impact
PovjerljivostCjelovitostDostupnost
NONE LOW HIGH
CVSS vektor CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
Zadnje važnije ažuriranje 04-12-2025 - 17:15
Objavljeno 03-12-2025 - 20:16