CVE-2026-54342 - TLS Certificate Verification Disabled on CXF Transport Clients in epa4all
Summary
This entry details a vulnerability found in the target system. The exploit was published on 2026-08-02 and has garnered 6 views from the community. It is classified under the remote category. Users are advised to review the source code in the Detail tab for technical specifics.
Zafiyet Ozet Bilgileri
Zafiyet Detayı (Turkce)
epa4all'da, 2026-05-20 sürümünden önce, epa4all ile herhangi bir arka uç (ePA Aktensystem, Konnektor, IDP, TSS) arasındaki ağ yolundaki bir saldırgan, kendinden imzalı bir TLS sertifikası sunabilir ve bağlantıyı kesebilir. VAU dışı bağlantılar (Konnektor, IDP) için bu, akıllı kart işlemleri de dahil olmak üzere iç trafiğin doğrudan okunmasına ve değiştirilmesine olanak tanır…
Orijinal Aciklama (Ingilizce)
CVE ID, Product, Vendor ... Pricing Browse by Apps View All Apps Splunk Slack Webhook Teams Jira Chrome API