Impact
The vulnerability lies in Imprivata Enterprise Access Management’s inability to rotate its RSA key pair after deployment when it generates an X.509 certificate. Because the same key pair is used indefinitely, the system does not adhere to best practices of cryptographic key management. This creates a risk that a compromised private key could be used to forge trusted certificates, enabling unauthorized authentication or the injection of false identities over time.
Affected Systems
Products affected are Imprivata Enterprise Access Management for all versions up to and including 26.2.6. The vulnerability was reported for releases 26.2.6 and earlier, which lack a mechanism to generate a new RSA key pair after the initial deployment.
Risk and Exploitability
No CVSS score is provided, and EPSS data is unavailable, so the quantified risk is not stated. The vulnerability does not describe an immediate active exploit path; rather, it exposes a long‑term risk by allowing an attacker who obtains the static key to create valid certificates. The lack of a KEV listing indicates no known exploits have been observed. The likely attack vector would be an internal actor or a compromised system with access to the key material, which can then produce genuine certificates. Until a patch is applied, the exposed risk remains a potential for future credential compromise.
OpenCVE Enrichment