SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted headers.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 02 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted headers. | |
| Title | S/MIME Decryption Impersonation | |
| First Time appeared |
Seppmail
Seppmail seppmail Secure Email Gateway |
|
| Weaknesses | CWE-20 | |
| CPEs | cpe:2.3:a:seppmail:seppmail_secure_email_gateway:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Seppmail
Seppmail seppmail Secure Email Gateway |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2026-04-02T08:49:31.012Z
Reserved: 2026-03-04T09:08:07.342Z
Link: CVE-2026-29143
No data.
Status : Received
Published: 2026-04-02T09:16:23.123
Modified: 2026-04-02T09:16:23.123
Link: CVE-2026-29143
No data.
OpenCVE Enrichment
No data.
Weaknesses