Home
MEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:NDefault status
unaffected
Any version before 15.0.1
affected
Description
SEPPmail Secure Email Gateway before version 15.0.1 does not properly communicate PGP signature verification results, leaving users unable to detect forged emails.
Problem types
CWE-347 Improper Verification of Cryptographic Signature
Product status
Any version before 15.0.1
Timeline
| 2025-10-31: | Vulnerability disclosed to SEPPmail |
| 2026-01-06: | SEPPmail version 15.0.1 released |
Credits
Andris Suter-Dörig
Matteo Scarlata
Kenny Paterson
References
downloads.seppmail.com/extrelnotes/150/ERN15.0.html