CVE-2020-11631 is a vulnerability affecting PrimeKey EJBCA versions prior to 6.15.2.6 and 7.x prior to 7.3.1.2. A malicious user can trigger an error state in the CA UI, which can then be leveraged to exploit other bugs, potentially leading to privilege escalation and remote code execution. This medium severity vulnerability (CVSS 6.5) requires at least one accessible port without client certificate authentication (e.g., 8442 or 8080) for exploitation. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.15.2.6CPE matchmatch criteria | cpe:2.3:a:primekey:ejbca:*:*:*:*:enterprise:*:*:* | ||
>= 7.0.0, < 7.3.1.2CPE matchmatch criteria | cpe:2.3:a:primekey:ejbca:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.