SEPPmail Secure Email Gateway
cpe:2.3:a:seppmail:seppmail:*:*:*:*:*:*:*
- < 15.0.3
A vulnerability exists in SEPPmail Secure Email Gateway versions prior to 15.0.3, where the inner message of S/MIME-encrypted MIME entities is not properly authenticated. This flaw allows an attacker to manipulate trusted headers. The issue is particularly relevant for users relying on S/MIME encryption, as it could lead to unauthorized control over email headers, potentially facilitating phishing or spoofing attacks.
Exploitation of this vulnerability could result in S/MIME decryption impersonation, allowing attackers to manipulate email headers and possibly impersonate trusted contacts.
Users can update to SEPPmail Secure Email Gateway version 15.0.3 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.