PT-2026-77223 · Epa · Epa
CVE-2026-52723
·
Published
2026-08-18
·
Updated
2026-08-18
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ePA 3.x Integration versions prior to 1.3.0
Description
The software performs VAU server certificate validation in the
app/vau/VAUProtokoll.py file without anchoring the signed vau server pub keys and AUT VAU CertData certificate path to independent trusted material. Additionally, TLS certificate verification is disabled. A network-positioned attacker between the DiGA backend and the ePA system can intercept the VAU handshake and provide attacker-controlled certificate and key material to satisfy a circular trust relationship. This allows the attacker to impersonate the VAU server, control negotiated session keys, and read or modify all encrypted VAU traffic.Recommendations
Update to version 1.3.0.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Epa