SEPPmail Secure Email Gateway GINA Account Second-Password Bypass Vulnerability

Vulnerability

A vulnerability in SEPPmail Secure Email Gateway versions prior to 15.0.3 allows an attacker with access to a victim's GINA account to bypass a second-password verification and read protected emails. This issue arises from improper handling of authentication checks, enabling unauthorized access to sensitive email content.

Impact

Exploitation of this vulnerability could lead to unauthorized reading of protected emails by bypassing the second-password check for GINA accounts.

Remediation

Users can update to SEPPmail Secure Email Gateway version 15.0.3 or later, where this vulnerability has been fixed.

Added: Apr 2, 2026, 9:22 AM
Updated: Apr 2, 2026, 9:22 AM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
0.6
exploitability
5.4
remediation
7.7
relevance
5.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.