Impact
The vulnerability is a command injection flaw in the privileged configuration handling of SEPPmail Secure Email Gateway. When an authenticated administrator submits configuration data, the system fails to properly sanitize input, allowing crafted strings to be interpreted as operating‑system commands. Successful exploitation enables the attacker to run arbitrary commands with the privileges of the gateway process, leading to full control over the affected device and any connected resources.
Affected Systems
SEPPmail AG’s Secure Email Gateway products are affected, specifically all releases prior to version 15.0.7. Users running any 15.0.x build below 15.0.7 should verify their deployment.
Risk and Exploitability
The CVSS score of 8.6 reflects a high severity and the absence of mitigation controls in normal operation. The EPSS score is 1%, indicating a low but non‑zero likelihood that this vulnerability is being actively exploited. The flaw is known and requires an authenticated administrator, meaning that an insider threat or compromised admin credentials can trigger the exploit. The issue is not listed in CISA’s KEV catalog, yet its impact and the ability for an attacker to execute arbitrary commands with elevated privileges make it a critical risk for any exposed or compromised administrator accounts.
OpenCVE Enrichment