PT-2026-64407 · Epa4All · Epa4All
CVE-2026-54342
·
Published
2026-07-24
·
Updated
2026-07-24
CVSS v3.1
8.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
epa4all versions prior to 2026-05-20
Description
An attacker positioned on the network path between the software and any backend (ePA Aktensystem, Konnektor, IDP, or TSS) can intercept the connection by presenting a self-signed TLS certificate. For non-VAU connections, such as those with Konnektor or IDP, this allows the attacker to read and modify internal traffic, including OIDC authentication exchanges and smartcard operations. For the ePA backend, the lack of TLS verification serves as a transport-level enabler for a Man-in-the-Middle (MITM) attack.
Recommendations
Update to version 2026-05-20.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Epa4All