Impact
An attacker on the network path between the ePA service and the Konnektor can present
any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This
includes patient identifiers (KVNR), SMC-B card operations (authentication, signing),
document content, and credential exchanges.
Patches
#36
Workarounds
Use the library directly instead of the REST wrapper.
References
Credits
Machine Spirits (contact@machinespirits.de)
- Dr. rer. nat. Simon Weber
- Dipl.-Inf. Volker Schönefeld
- Chiara Fliegner
Impact
An attacker on the network path between the ePA service and the Konnektor can present
any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This
includes patient identifiers (KVNR), SMC-B card operations (authentication, signing),
document content, and credential exchanges.
Patches
#36
Workarounds
Use the library directly instead of the REST wrapper.
References
Credits
Machine Spirits (contact@machinespirits.de)