CVE-2024-45341

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 28, 2025

Summary

CVE-2024-45341 is a cybersecurity vulnerability that arises when a certificate with an IPv6 address containing a zone ID incorrectly satisfies a URI name constraint in private PKI environments. This issue occurs due to the use of URIs in certificates, which are not permitted in the web Public Key Infrastructure (PKI). Consequently, only private PKIs that utilize URIs in their certificates are at risk. This disparity between the web PKI standard and private PKI configurations can lead to security misconfigurations and potential certificate validation errors.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share