PT-2020-16057 · Primekey · Primekey Ejbca

Published

2020-09-11

·

Updated

2024-03-06

·

CVE-2020-25276

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions PrimeKey EJBCA versions 6.x through 7.4.0
Description An issue was discovered where no revocation check is performed on a client certificate when enrolling over the EST protocol. This can affect systems with EST configured, using client certificates for enrollment authentication, and having a revoked certificate belonging to a role authorized for new end entity enrollment.
Recommendations For PrimeKey EJBCA versions 6.x through 7.4.0, to mitigate this issue, remove any revoked client certificates from their respective roles until an upgrade to a fixed version is possible. Upgrade to version 7.4.1 or later to completely resolve the issue.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BIT-EJBCA-2020-25276
CVE-2020-25276

Affected Products

Primekey Ejbca