CyberRota Analysis
AI-GeneratedAn unauthenticated client can exploit this vulnerability to query the Security Domain hosts inventory, allowing them to obtain detailed information about internal PKI/CA hosts and their roles without any authentication. This exposure could lead to further attacks on the security infrastructure by revealing critical topology and subsystem details. Organizations utilizing affected products should prioritize remediation to protect their internal security architecture from potential reconnaissance and exploitation.
Original NVD Description
An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.