WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity

VU#273940: Enterprise Access Management EAM does not rotate RSA keys

System with various wires managing access to centralized resource of server in data center
Illustrative photo.Photo by Brett Sayles on Pexels

What happened

After reviewing the product documentation and engaging Imprivata support, it was confirmed that no supported mechanism exists to rotate this RSA key pair after deployment. Overview Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below.

The product provides no supported mechanism to rotate its RSA key pair after deployment, meaning the same key pair is used indefinitely to generate the appliance's X.509 certificate. If perfect forward secrecy is not enforced, previously captured traffic can also be decrypted retroactively.

Because the key pair cannot be rotated, this access persists until the appliance is redeployed. The vendor is aware of the issue, which they are tracking internally, and is reported to be working toward a resolution.

Key facts

  • The product — provides: no supported mechanism to rotate its RSA key pair after deployment, meaning the same key pair is used indefinitely to generate the appliance's X.509 certificate

Sources & evidence