Impact
In epa4all versions older than 2026‑05‑20, the CXF transport clients skip TLS certificate verification, allowing an adversary on the network path to present a self‑signed certificate and intercept the communication. This control failure permits passive eavesdropping and active tampering of all exchanged data, including smart‑card transactions and OpenID Connect authentication flows. For the ePA backend, the absence of verification also enables the VAU MITM attack described in advisories.
Affected Systems
The vulnerability affects the med‑united epa4all product in every release prior to 2026‑05‑20. No further affected versions are listed beyond that cutoff, indicating that versions from 2026‑05‑20 onward have the issue fixed.
Risk and Exploitability
The CVSS score of 8.1 places the flaw in the high severity range, while the EPSS score of <1% indicates a low current exploitation probability yet the impact remains significant. It is not referenced in the CISA KEV catalog. An attacker would need to position themselves between an epa4all client and its backend to present a rogue certificate; the client accepts it without verification, exposing the communication to passive and active attacks.
OpenCVE Enrichment