Non-rotatable RSA Key Pair in Imprivata Enterprise Access Management (EAM) <=26.2.6
AI analysis
Imprivata Enterprise Access Management (EAM) versions 26.2.6 and earlier generate an X.509 certificate from an RSA key pair that cannot be rotated after deployment, so the same long-lived key is used indefinitely. This is a key-management weakness rather than a flaw an attacker triggers directly: the impact materializes if the private key is ever compromised through a separate intrusion, side-channel, or future cryptanalytic advance. An attacker who obtains the key can forge or spoof the certificate indefinitely, enabling impersonation of the EAM service or man-in-the-middle interception of sessions that trust it, with no clean rotation path to invalidate the stolen key. Affected parties are organizations running Imprivata EAM 26.2.6 or older, which Imprivata deploys primarily in healthcare settings such as hospitals and health systems. There is no CVSS score yet, no public proof of concept, and no known exploitation in the wild.
What to do: Plan an upgrade to an Imprivata EAM release later than 26.2.6 once the vendor ships key-rotation support, and track CERT advisory VU#273940 for fixed-version details. In the meantime, treat the appliance's RSA private key as high-value: harden and restrict access to the EAM server and its key store, segment it from general networks, and monitor logs and certificate transparency or trust stores for any unexpected certificates matching the deployment's key. If key compromise is suspected, engage Imprivata support immediately, since in-place rotation is not possible on affected versions.
Affected
| Imprivata Enterprise Access Management (EAM) | <=26.2.6 |
Estimated exposure
large≈ thousands of enterprise deployments (healthcare organizations), covering an estimated 1M+ clinician end users — Imprivata reports a customer base of thousands of hospitals and health systems representing millions of users, and EAM is typically deployed as internal infrastructure, so internet-exposed system counts are low despite the large user…