Home
HIGH: 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:H/SA:NDefault status
unaffected
Any version before 15.0.1
affected
Description
SEPPmail Secure Email Gateway before version 15.0.1 incorrectly interprets email addresses in the email headers, causing an interpretation conflict with other mail infrastructure that allows an attacker to fake the source of the email or decrypt it.
Problem types
CWE-436 Interpretation Conflict
Product status
Any version before 15.0.1
Timeline
| 2025-10-31: | Vulnerability disclosed to SEPPmail |
| 2026-01-06: | Version 15.0.1 released |
Credits
Andris Suter-Dörig
Matteo Scarlata
Kenny Paterson
References
downloads.seppmail.com/extrelnotes/150/ERN15.0.html