← Back

CVE-2020-25276

nvd nist
Published: Sep 11, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.4
Source: NVD

Description

An issue was discovered in PrimeKey EJBCA 6.x and 7.x before 7.4.1. When using a client certificate to enroll over the EST protocol, no revocation check is performed on that certificate. This vulnerability can only affect a system that has EST configured, uses client certificates to authenticate enrollment, and has had such a certificate revoked. This certificate needs to belong to a role that is authorized to enroll new end entities. (To completely mitigate this problem prior to upgrade, remove any revoked client certificates from their respective roles.)

Affected (1)

Products: Primekey: Ejbca
1 product
Ejbca
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 7.0.0 to 7.4.1

Timeline

No history available yet.