SEPPmail Secure Email Gateway S/MIME Decryption Impersonation Vulnerability

Vulnerability

A vulnerability exists in SEPPmail Secure Email Gateway versions prior to 15.0.3, where the inner message of S/MIME-encrypted MIME entities is not properly authenticated. This flaw allows an attacker to manipulate trusted headers. The issue is particularly relevant for users relying on S/MIME encryption, as it could lead to unauthorized control over email headers, potentially facilitating phishing or spoofing attacks.

Impact

Exploitation of this vulnerability could result in S/MIME decryption impersonation, allowing attackers to manipulate email headers and possibly impersonate trusted contacts.

Remediation

Users can update to SEPPmail Secure Email Gateway version 15.0.3 or later, where this vulnerability has been addressed.

Added: Apr 2, 2026, 9:17 AM
Updated: Apr 2, 2026, 9:17 AM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
0.6
exploitability
7.6
remediation
7.7
relevance
5.1
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.