« Volver al listado

CVE-2026-45574

Estado: AplazadaAlta (8.1)—

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This includes patient identifiers (KVNR), SMC-B card operations (authentication, signing), document content, and credential exchanges. This vulnerability is fixed in 1.2.2.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CWE-295 (validación TLS insuficiente) en red adyacente (AV:A) permite ataque Man-in-the-Middle. Intercepta tráfico SOAP, credenciales, datos de pacientes y operaciones de firmado.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-45574",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-45574",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-27T13:20:59.307934Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "oviva-ag",
          "product": "epa4all-client",
          "versions": [
            {
              "status": "affected",
              "version": "< 1.2.2"
            }
          ]
        },
        {
          "vendor": "com.oviva.telematik",
          "product": "epa4all-client",
          "versions": [
            {
              "status": "affected",
              "version": "< 1.2.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-26T22:16:43.887",
  "references": [
    {
      "url": "https://github.com/oviva-ag/epa4all-client/pull/36",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/oviva-ag/epa4all-client/security/advisories/GHSA-5hhf-xmfx-4vvr",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-295"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This includes patient identifiers (KVNR), SMC-B card operations (authentication, signing), document content, and credential exchanges. This vulnerability is fixed in 1.2.2."
    },
    {
      "lang": "es",
      "value": "epa4all-client es el Cliente Java para epa4all / ePA 3.0 en la Telematik Infrastruktur. Antes de 1.2.2, un atacante en la ruta de red entre el servicio ePA y el Konnektor puede presentar cualquier certificado TLS (autofirmado, caducado, CN incorrecto) e interceptar todo el tráfico SOAP. Esto incluye identificadores de paciente (KVNR), operaciones de tarjeta SMC-B (autenticación, firma), contenido de documentos e intercambio de credenciales. Esta vulnerabilidad está corregida en 1.2.2."
    }
  ],
  "lastModified": "2026-07-24T12:10:00.210",
  "sourceIdentifier": "security-advisories@github.com"
}