Project Subscriptions
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gqx7-6552-67hf | Improper Verification of Cryptographic Signature in com.oviva.telematik:epa4all-client |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 28 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Com.oviva.telematik
Com.oviva.telematik epa4all-client Oviva-ag Oviva-ag epa4all-client |
|
| Vendors & Products |
Com.oviva.telematik
Com.oviva.telematik epa4all-client Oviva-ag Oviva-ag epa4all-client |
Tue, 26 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection between the client and the IDP (within the TI network) can substitute a forged discovery document. The forged document redirects uri_puk_idp_enc and uri_puk_idp_sig to attacker-controlled URLs. The client then encrypts the SMC-B-signed challenge response to the attacker's encryption key and POSTs it to the attacker's auth endpoint. This captures the signed authentication material. This vulnerability is fixed in 1.2.2. | |
| Title | epa4all-client: Improper Verification of Cryptographic Signature | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-28T14:11:30.565Z
Reserved: 2026-05-12T19:00:14.600Z
Link: CVE-2026-45575
Updated: 2026-05-28T14:11:26.946Z
Status : Deferred
Published: 2026-05-26T21:16:40.373
Modified: 2026-05-27T19:41:21.417
Link: CVE-2026-45575
No data.
OpenCVE Enrichment
Updated: 2026-05-27T10:08:25Z
Github GHSA