PT-2026-77221 · Epa · Epa
CVE-2026-50578
·
Published
2026-08-18
·
Updated
2026-08-18
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ePA 3.x Integration versions prior to 1.3.0
Description
The software disables TLS certificate verification for ePA connections in
app/vau/VAUProtokoll.py and Konnektor connections in app/konnektor/Konnektor.py. A network-positioned attacker can present an arbitrary certificate to terminate the TLS connection and intercept ePA traffic. The VAU protocol lacks an effective fallback as its application-layer certificate validation is also compromised. Additionally, the Konnektor session sets self.session.verify to False while the client authenticates using self.session.cert, allowing an attacker impersonating the Konnektor to receive the client's mutual TLS certificate exchange and observe smartcard operations.Recommendations
Update to version 1.3.0.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Epa