LiveActive security incident?Get immediate response
CVE Record

CVE-2021-40087: An issue was discovered in PrimeKey EJBCA before 7.6.0.

An issue was discovered in PrimeKey EJBCA before 7.6.0. When audit logging changes to the alias configurations of various protocols that use an enrollment secret, any modifications to the secret were logged in cleartext in the audit log (that can only be viewed by an administrator). This affects use of any of the following protocols: SCEP, CMP, or EST.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

EJBCA versions before 7.6.0 could write enrollment secrets into audit logs when administrators changed certain protocol alias settings. This is not described as public remote exploitation; the concern is that sensitive secrets may persist in logs accessible to administrators or log systems.

Executive priority

Treat as a focused credential-exposure issue. Prioritize remediation where EJBCA supports certificate enrollment workflows or where audit logs are accessible outside a small trusted administrator group.

Technical view

When SCEP, CMP, or EST alias configurations using an enrollment secret were modified, the secret value could be logged in cleartext in EJBCA audit logs. The source states audit logs are administrator-viewable. Affected scope is PrimeKey EJBCA before 7.6.0.

Likely exposure

Organizations running PrimeKey EJBCA before 7.6.0 with SCEP, CMP, or EST aliases using enrollment secrets are the likely exposure group, especially where audit logs are retained, exported, or broadly administered.

Exploitation context

The provided sources do not report active exploitation, and this CVE is not marked KEV. Practical risk depends on who can view or retrieve audit logs and whether logged enrollment secrets remain valid.

Researcher notes

Evidence is concise and vendor-specific. No CVSS, CWE, exploit evidence, or detailed patch note text is included in the bundle. The core validated behavior is cleartext logging of modified enrollment secrets for SCEP, CMP, and EST aliases before 7.6.0.

Mitigation direction

  • Upgrade EJBCA to 7.6.0 or later, following vendor guidance.
  • Identify SCEP, CMP, and EST aliases using enrollment secrets.
  • Rotate affected enrollment secrets after stopping further cleartext logging.
  • Restrict administrator and log-platform access to EJBCA audit logs.
  • Review retained or forwarded logs for exposed secrets.

Validation and detection

  • Confirm the deployed EJBCA version is not earlier than 7.6.0.
  • Check whether SCEP, CMP, or EST aliases use enrollment secrets.
  • Review audit-log retention and forwarding destinations.
  • Determine whether enrollment-secret changes occurred before remediation.
  • Verify exposed or possibly exposed secrets were rotated.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Credential and access behavior lookup

The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-40087 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.