« Volver al listado

CVE-2026-45575

Estado: AplazadaAlta (7.4)—

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection between the client and the IDP (within the TI network) can substitute a forged discovery document. The forged document redirects uri_puk_idp_enc and uri_puk_idp_sig to attacker-controlled URLs. The client then encrypts the SMC-B-signed challenge response to the attacker's encryption key and POSTs it to the attacker's auth endpoint. This captures the signed authentication material. This vulnerability is fixed in 1.2.2.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

MITM en TLS entre cliente Java y IDP captura credenciales firmadas; atacante sustituye documento de descubrimiento para redirigir URIs a servidores controlados, interceptando material de autenticación (SMC-B).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-45575",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-45575",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-28T14:11:18.105155Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.4,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "oviva-ag",
          "product": "epa4all-client",
          "versions": [
            {
              "status": "affected",
              "version": "< 1.2.2"
            }
          ]
        },
        {
          "vendor": "com.oviva.telematik",
          "product": "epa4all-client",
          "versions": [
            {
              "status": "affected",
              "version": "< 1.2.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-26T21:16:40.373",
  "references": [
    {
      "url": "https://github.com/oviva-ag/epa4all-client/pull/36",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/oviva-ag/epa4all-client/security/advisories/GHSA-gqx7-6552-67hf",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-347"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection between the client and the IDP (within the TI network) can substitute a forged discovery document. The forged document redirects uri_puk_idp_enc and uri_puk_idp_sig to attacker-controlled URLs. The client then encrypts the SMC-B-signed challenge response to the attacker's encryption key and POSTs it to the attacker's auth endpoint. This captures the signed authentication material. This vulnerability is fixed in 1.2.2."
    },
    {
      "lang": "es",
      "value": "epa4all-client es el Cliente Java para epa4all / ePA 3.0 en la Telematik Infrastruktur. Anterior a la 1.2.2, un atacante que puede realizar un MitM a la conexión TLS entre el cliente y el IDP (dentro de la red TI) puede sustituir un documento de descubrimiento falsificado. El documento falsificado redirige uri_puk_idp_enc y uri_puk_idp_sig a URLs controladas por el atacante. El cliente entonces cifra la respuesta al desafío firmada con SMC-B con la clave de cifrado del atacante y la envía mediante POST al endpoint de autenticación del atacante. Esto captura el material de autenticación firmado. Esta vulnerabilidad está corregida en la versión 1.2.2."
    }
  ],
  "lastModified": "2026-07-24T11:10:00.170",
  "sourceIdentifier": "security-advisories@github.com"
}