Executive brief
SEPPmail Secure Email Gateway, a solution used for secure corporate email communication, contains a vulnerability in its PDF encryption module. An attacker can exploit this flaw to create unauthorized files on the system, potentially placing them in locations accessible via the web. This could lead to the compromise of the gateway's integrity or the hosting of malicious content on the appliance.
Technical details
A path traversal vulnerability (CWE-22) exists in the PDF module of SEPPmail Secure Email Gateway when handling attachment filenames during encrypted PDF generation. The root cause is improper validation of filenames for embedded attachments, which allows an attacker with low privileges to use traversal sequences to write files to arbitrary locations on the filesystem, including web-accessible directories. This vulnerability was addressed in version 15.0.5 by improving filename handling. The attack requires network access and low-level authentication (PR:L) to trigger the PDF generation process.
Affected products
- SEPPmail AG Secure Email Gateway before 15.0.5
Timeline
- 2026-05-30: patched: Fixed in version 15.0.5
- 2026-06-18: disclosed: CVE published and NVD entry created