PT-2026-77220 · Unknown · Epa 3.X Integration
CVE-2026-50577
·
Published
2026-08-18
·
Updated
2026-08-27
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ePA 3.x Integration versions prior to 1.3.0
Description
The software fails to update the
request counter in the app/vau/VAUProtokoll.py file when constructing VAU messages. This results in the server reusing AES-GCM nonce and key combinations across responses. A network attacker can collect repeated ciphertexts to recover the XOR of plaintexts and use predictable inner HTTP headers and JSON fields to access sensitive patient health records. Additionally, the reuse of nonces allows for the recovery of the GHASH authentication key via the Joux forbidden attack, enabling the forgery of AES-GCM messages and the injection of malicious responses. The system also fails to maintain the last response counter, which weakens replay and ordering validation.Recommendations
Update ePA 3.x Integration to version 1.3.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Epa 3.X Integration