VU#273940: Enterprise Access Management EAM does not rotate RSA keys
What happened
After reviewing the product documentation and engaging Imprivata support, it was confirmed that no supported mechanism exists to rotate this RSA key pair after deployment. Overview Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below.
The product provides no supported mechanism to rotate its RSA key pair after deployment, meaning the same key pair is used indefinitely to generate the appliance's X.509 certificate. If perfect forward secrecy is not enforced, previously captured traffic can also be decrypted retroactively.
Because the key pair cannot be rotated, this access persists until the appliance is redeployed. The vendor is aware of the issue, which they are tracking internally, and is reported to be working toward a resolution.
Key facts
- The product — provides: no supported mechanism to rotate its RSA key pair after deployment, meaning the same key pair is used indefinitely to generate the appliance's X.509 certificate
Sources & evidence
- CERT/CC Vulnerability Notes Primary / official
VU#273940: Enterprise Access Management EAM does not rotate RSA keys ↗
https://kb.cert.org/vuls/id/273940