CVE-2026-45575
📛 CVE Title
(no title)
Description
Improper Verification of Cryptographic Signature in com.oviva.telematik:epa4all-client
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- high
- CVSS score
- 7.4 / 10
- CVSS vector
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N- Effective score
- 7.4 / 10 HIGH source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2026-45575
- Linked Threat
- CVE-2026-45575 — CVE-2026-45575
NVD / KEV / EPSS data refreshed 2026-05-25 00:07 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-32000 - Assigner
- GitHub_M
- Published
- May 26, 2026, 9:01:51 PM
- Updated
- May 28, 2026, 2:11:30 PM
- EUVD base score (CVSS 3.1)
-
7.4 / 10
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N - EUVD-reported EPSS
- 0.1200
- Vendors
- oviva-ag, com.oviva.telematik
- Products
-
epa4all-client (< 1.2.2)
- Aliases
-
GHSA-gqx7-6552-67hf
ENISA description: epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection between the client and the IDP (within the TI network) can substitute a forged discovery document. The forged document redirects uri_puk_idp_enc and uri_puk_idp_sig to attacker-controlled URLs. The client then encrypts the SMC-B-signed challenge response to the attacker's encryption key and POSTs it to the attacker's auth endpoint. This captures the signed authentication material. This vulnerability is fixed in 1.2.2.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (5)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://github.com/oviva-ag/epa4all-client/pull/36 tenable:github.com
- https://github.com/oviva-ag/epa4all-client/security/advisories/GHSA-gqx7-6552-67hf tenable:github.com
- https://www.first.org/epss/ tenable:www.first.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-45575 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-45575 tenable:www.cve.org
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:blog.talosintelligence.com
Microsoft has released its monthly security update for May 2026 , which includes 137 vulnerabilities affecting a range of products, including 16 that Microsoft marked as "critical".
2026-05-26 02:55 UTC -
web:cybersecuritynews.com
No patch has been released yet; Microsoft has instead issued a multi-step manual mitigation guide while a formal security update is prepared. Windows BitLocker Security Bypass The vulnerability originates in WinRE's handling of the BootExecute registry value under HKLM\ControlSet001\Control\Session Manager.
2026-05-26 02:55 UTC -
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
2026-05-26 02:55 UTC -
web:pupuweb.com
Microsoft has updated the mitigation guidance in CVE - 2026 -45585, a Windows BitLocker security feature bypass vulnerability. The updated guidance replaces previously documented manual mitigation steps with a script that helps reduce exposure while a future security update is developed to address this vulnerability.
2026-05-26 02:55 UTC -
web:windowsreport.com
The newly exposed Windows security flaw, dubbed "YellowKey," has become a major headache for Microsoft. After the exploit details leaked publicly alongside a working proof-of-concept, the company has now rushed out official mitigation guidance while it prepares a permanent fix . The vulnerability reportedly targets BitLocker-protected systems and could allow attackers direct access to ...
2026-05-26 02:55 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's April 2026 Patch Tuesday with security updates for 167 flaws, including 2 zero-day vulnerabilities.
2026-05-26 02:55 UTC -
web:www.crowdstrike.com
Microsoft's April 2026 Patch Tuesday addresses 164 CVEs , featuring 8 Critical vulnerabilities, one exploited zero-day, and one disclosed zero-day.
2026-05-26 02:55 UTC -
web:www.notebookcheck.net
Microsoft released mitigation steps for YellowKey ( CVE - 2026 -45585), a BitLocker bypass that grants physical attackers access to encrypted Windows drives.
2026-05-26 02:55 UTC -
web:www.securityweek.com
Microsoft has announced mitigations for CVE - 2026 -45585, a BitLocker bypass triggered via FsTx in Windows Recovery.
2026-05-26 02:55 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-05-26 02:55 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.