CVE-2026-45575
HIGHepa4all-client: Improper Verification of Cryptographic Signature
Title source: cnaDescription
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection between the client and the IDP (within the TI network) can substitute a forged discovery document. The forged document redirects uri_puk_idp_enc and uri_puk_idp_sig to attacker-controlled URLs. The client then encrypts the SMC-B-signed challenge response to the attacker's encryption key and POSTs it to the attacker's auth endpoint. This captures the signed authentication material. This vulnerability is fixed in 1.2.2.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/oviva-ag/epa4all-client/security/advisories/GHSA-gqx7-6552-67hf
X_Refsource_Misc x_refsource_misc
https://github.com/oviva-ag/epa4all-client/pull/36
Scores
CVSS v3
7.4
EPSS
0.0012
EPSS Percentile
2.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-347
Status
published
Products (3)
com.oviva.telematik/epa4all-client
0 - 1.2.2Maven
com.oviva.telematik/epa4all-client
< 1.2.2
oviva-ag/epa4all-client
< 1.2.2
Published
May 26, 2026
Tracked Since
May 27, 2026