Impact
Cloudflare’s Universal SSL automatically supplies a permissive CAA record that overrides any customer‑configured CAA entries. include the RFC 8657 accounturi or validationmethods tags restrictive CAA set, bypassing the binding checks defined by RFC 8659. This constitutes a protection‑mechanism failure (CWE‑693) and allows an attacker who controls an ACME account listed in the zone’s CAA record to obtain a browser‑trusted TLS certificate for the domain if they can satisfy domain‑control validation. The issued certificate can then be used to conduct a man‑in‑the‑middle attack against clients that trust the domain’s certificate.
Affected Systems
All zones using Cloudflare Universal SSL; no specific affected version information is provided in the advisory, so all current deployments are potentially impacted.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity. The EPSS score is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of widespread exploitation. Attackers would still need an ACME account at a listed certificate authority and to satisfy domain‑control validation across the geographically distributed perspectives used by modern issuers, making exploitation non‑trivial. However, any misissued browser‑trusted Certificate Transparency, offering a detection trail.
OpenCVE Enrichment