Impact
Vault’s PKI secrets engine ACME server can issue certificates that include subject alternative names (SANs) that have not been validated by the ACME challenge, allowing an attacker to obtain a certificate with unverified identity claims. This flaw is classified as a weakness in untrusted input handling (CWE‑345) and could enable an attacker to impersonate other systems that trust certificates issued by the affected Vault PKI mount.
Affected Systems
The vulnerability affects HashiCorp Vault Community Edition versions earlier than 2.1.2 and Vault Enterprise version 2.1.2 and earlier, specifically Enterprise releases 1.21.12, 1.20.17, and 1.19.23. Any deployment of the PKI secrets engine that uses the default directory policy and has not been updated to a patched version is at risk.
Risk and Exploitability
The CVSS score for this issue is 5.9, indicating a moderate severity, and the EPSS score is not available. It is not listed in the CISA Known Exploited Vulnerability catalog. The likely attack vector is through a client using the ACME protocol against a Vault instance that has the default directory policy enabled; the attacker can supply an ACME challenge that does not verify the desired SANs and receive a certificate containing those unvalidated identities.
OpenCVE Enrichment