« Volver al listado

Epa4all

Epa4all-client: vulnerabilidades y CVE

Epa4all-client tiene 3 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE3
Últimos 12 meses3
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-45574Alta (8.1)0.19%—26 may 2026
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS certificate…
CVE-2026-47672Media (6.5)0.24%—26 may 2026
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. In 1.2.4 and earlier, any network-reachable caller can write arbitrary documents to any patient's electronic health record…
CVE-2026-45575Alta (7.4)0.15%—26 may 2026
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection between the client and the IDP (within the TI network) can substitute a…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1040 Network Sniffing1
  2. T1210 Exploitation of Remote Services1
  3. T1557 Adversary-in-the-Middle1
  4. T1557.002 ARP Cache Poisoning1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Epa4all