The GINA web interface in SEPPmail Secure Email Gateway before version 15.0.1 does not properly check attachment filenames in GINA-encrypted emails, allowing an attacker to access files on the gateway.
The GINA interface in SEPPmail Secure Email Gateway does not perform proper validation of attachment names in messages encrypted with the GINA mechanism. An attacker can craft an email message with an attachment whose name contains path traversal sequences (e.g., '../../'), forcing the gateway to read files outside the intended directory. This makes it possible to gain access to system or configuration files on the gateway device.
An attacker can read any files accessible to the process handling the GINA interface, which may lead to disclosure of configuration data, credentials, cryptographic keys, or other sensitive information stored on the gateway. If access to critical files is obtained, further compromise of the environment is possible.
SEPPmail Secure Email Gateway should be updated to version 15.0.1 or newer, in which the vulnerability has been removed. Details are available in the manufacturer's release notes at: https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html#seppmail-vulnerability-disclosure
SEPPmail Secure Email Gateway in versions prior to 15.0.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSeppmail
APPSeppmail< 15.0.1
Related vulnerabilities
RCE przez path traversal i zapis pliku w SeppMail User Web Interface
Command injection w SEPPmail Secure Email Gateway poprzez hasło szyfrowania PDF
SEPPmail Secure Email Gateway before version 15.0.1 incorrectly interprets email addresses in the email header...
SEPPmail Secure Email Gateway before version 15.0.1 does not properly sanitize the headers from S/MIME protect...
SEPPmail Secure Email Gateway before version 15.0.1 improperly validates S/MIME certificates issued for email ...