SEPPmail Secure Email Gateway S/MIME Certificate Validation Vulnerability Allowing Signature Spoofing

Vulnerability

A vulnerability in SEPPmail Secure Email Gateway versions prior to 15.0.1 allows for improper validation of S/MIME certificates. The issue arises with certificates issued to email addresses containing whitespaces, which can be exploited to spoof signatures.

Impact

Exploitation of this vulnerability could lead to unauthorized signature spoofing in S/MIME communications.

Remediation

Users can update to SEPPmail Secure Email Gateway version 15.0.1 or later to address this vulnerability.

Added: Mar 4, 2026, 9:18 AM
Updated: Mar 4, 2026, 9:18 AM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
2.5
exploitability
7.6
remediation
7.7
relevance
3.5
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.