Home
MEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:NDefault status
unaffected
Any version before 15.0.1
affected
Description
SEPPmail Secure Email Gateway before version 15.0.1 decrypts inline PGP messages without isolating them from surrounding unencrypted content, allowing exposure of sensitive information to an unauthorized actor.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
Any version before 15.0.1
Timeline
| 2025-10-31: | Vulnerability disclosed to SEPPmail |
| 2026-01-06: | SEPPmail version 15.0.1 released |
Credits
Andris Suter-Dörig
Matteo Scarlata
Kenny Paterson
References
downloads.seppmail.com/extrelnotes/150/ERN15.0.html