PT-2020-16057 · Primekey · Primekey Ejbca
Published
2020-09-11
·
Updated
2024-03-06
·
CVE-2020-25276
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
PrimeKey EJBCA versions 6.x through 7.4.0
Description
An issue was discovered where no revocation check is performed on a client certificate when enrolling over the EST protocol. This can affect systems with EST configured, using client certificates for enrollment authentication, and having a revoked certificate belonging to a role authorized for new end entity enrollment.
Recommendations
For PrimeKey EJBCA versions 6.x through 7.4.0, to mitigate this issue, remove any revoked client certificates from their respective roles until an upgrade to a fixed version is possible.
Upgrade to version 7.4.1 or later to completely resolve the issue.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Primekey Ejbca