LiveActive security incident?Get immediate response
CVE Record

CVE-2021-36096: Support Bundle includes S/Mime and PGP secret or PIN

Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions; 8.0.x version 8.0.15 and prior versions.

MediumCVSS 5.2Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

Affected OTRS support bundles may accidentally include private S/MIME or PGP keys when the containing folder is not hidden. This turns a routine support artifact into sensitive key material. Business urgency depends on whether support bundles were generated, stored, or shared outside a tightly controlled administrative group.

Executive priority

Prioritize as moderate unless support bundles were shared externally or retained broadly. The main business risk is exposure of private mail encryption or signing keys, which can undermine confidentiality and trust in signed communications.

Technical view

CVE-2021-36096 is an information exposure issue in OTRS support bundle generation. The CVSS 3.1 vector is AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N, reflecting high confidentiality impact but requiring high privileges and user interaction. Affected versions include ((OTRS)) Community Edition 6.0.1 and later, OTRS 7.0.x through 7.0.28, and 8.0.x through 8.0.15.

Likely exposure

Exposure is likely limited to organizations running affected OTRS versions that generated support bundles while S/MIME or PGP secret material was in a non-hidden folder. Risk increases if bundles were attached to tickets, emailed, uploaded to vendors, or retained in shared storage.

Exploitation context

The bundle states no KEV listing, and no cited source confirms active exploitation. Practical abuse would depend on obtaining a generated support bundle containing private key material. The issue is not described as unauthenticated remote compromise; the CVSS vector requires high privileges and user interaction.

Researcher notes

Evidence is limited to CVE metadata and the OTRS advisory reference. The provided sources do not name a specific fixed version, exploit campaign, or complete workaround. Avoid assuming internet-scale exploitability; focus validation on affected versions, bundle generation history, and handling of generated artifacts.

Mitigation direction

  • Review the OTRS security advisory for vendor-supported update or configuration guidance.
  • Restrict support bundle generation and access to trusted administrators only.
  • Treat historical support bundles from affected systems as sensitive key material.
  • If bundles were shared externally, follow incident response for exposed cryptographic secrets.
  • Check vendor guidance before changing key storage behavior or product configuration.

Validation and detection

  • Inventory OTRS Community Edition 6.0.1 and later deployments.
  • Identify OTRS 7.0.x systems at or below 7.0.28.
  • Identify OTRS 8.0.x systems at or below 8.0.15.
  • Review whether support bundles were generated on affected systems.
  • Check where generated support bundles were stored, attached, or shared.
  • Assess whether S/MIME or PGP private material was present in non-hidden folders.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-200: Information exposure and cloud metadata lookup

Information exposure and SSRF weaknesses can make discovery, cloud metadata, and credential material review relevant. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Credential and access behavior lookup

The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-36096 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
5.2 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
5.2CVSS 3.1MediumCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N0.94.2Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

5.2Medium
CVSS 3.1 vector shape for CVE-2021-36096Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
OTRS AG((OTRS)) Community Edition6.0.1Listed
OTRS AGOTRS7.0.x, 8.0.xListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-200 · source CWE mapping

Exposure of Sensitive Information to an Unauthorized Actor

Exposure of Sensitive Information to an Unauthorized Actor represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.