All 4 CVE vulnerabilities found in ePA3-Service-OpenSource, with AI-generated Chinese analysis, references, and POCs.
Vendor: fbeta-GmbH
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-50577 | ePA 3.x Integration: AES-GCM Nonce Reuse via Frozen VAU Request Counter CWE-323 | 7.4 | High | 2026-08-18 |
| CVE-2026-50578 | ePA 3.x Integration: TLS Certificate Verification Universally Disabled CWE-295 | 7.5 | High | 2026-08-18 |
| CVE-2026-52723 | ePA 3.x Integration: VAU Server Authentication Bypass via Circular Certificate Trust CWE-295 | 9.1 | Critical | 2026-08-18 |
| CVE-2026-50576 | ePA 3.x Integration: HTTP Header Injection in VAU Inner Requests CWE-113 | 6.8 | Medium | 2026-08-18 |
All 4 known CVE vulnerabilities affecting ePA3-Service-OpenSource with full Chinese analysis, references, and POCs where available.