All 4 CVE vulnerabilities found in epa4all-client, with AI-generated Chinese analysis, references, and POCs.
Vendor: oviva-ag
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-44900 | epa4all-client: VAU Signature bypass CWE-295 | 8.1 | High | 2026-05-26 |
| CVE-2026-45574 | epa4all-client: TLS Certificate Validation Disabled in Production CWE-295 | 8.1 | High | 2026-05-26 |
| CVE-2026-45575 | epa4all-client: Improper Verification of Cryptographic Signature CWE-347 | 7.4 | High | 2026-05-26 |
| CVE-2026-47672 | epa4all-client: Unauthenticated REST API for Patient Record Writes CWE-306 | 6.5 | Medium | 2026-05-26 |
All 4 known CVE vulnerabilities affecting epa4all-client with full Chinese analysis, references, and POCs where available.