Vulnerabilidades en SEPPmail
25 resultadosAnálisis Vexday
SEPPmail apresenta 24 vulnerabilidades catalogadas, com apenas 2 de severidade crítica e nenhuma sob exploração ativa conhecida, reduzindo o risco imediato. A fraqueza dominante é validação inadequada de entrada (CWE-20), padrão típico em gateways de email, exigindo vigilância contínua em patches de entrada. O volume moderado e a baixa atividade recente (1 CVE em 90 dias) sugerem que o fornecedor não está no epicentro de campanhas de exploração, mas vulnerabilidades de validação neste segmento demandam monitoramento regular.
CVE-2022-41871MEDIUMSEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in thEPSS 1.0%CVE-2026-2743CRITICALSEPPmail User Web Interface Arbitrary File Write to RCEEPSS 0.8%CVE-2026-27442CRITICALzip_attachments Path TraversalEPSS 0.4%CVE-2026-27441CRITICALPDF Password CMDiEPSS 0.3%CVE-2026-29139HIGHGINA State Confusion Account TakeoverEPSS 0.3%CVE-2026-29135MEDIUMWebmail Password Tag Sanitization BypassEPSS 0.3%CVE-2026-29132MEDIUMESWmail-Verify BypassEPSS 0.3%CVE-2026-29143HIGHS/MIME Decryption ImpersonationEPSS 0.3%CVE-2026-2747MEDIUMPGP Mixed Plaintext and Encrypted ContentEPSS 0.3%CVE-2026-29133MEDIUMUID Regex BypassEPSS 0.2%CVE-2026-29131MEDIUMPGP Decryption Recipient LDAP InjectionEPSS 0.2%CVE-2026-29134MEDIUMGINA Domain SwitchEPSS 0.2%CVE-2026-27443HIGHS/MIME Decryption Tag Sanitization BypassEPSS 0.2%CVE-2026-29138MEDIUMPGP Decryption Sender LDAP InjectionEPSS 0.2%CVE-2026-27444HIGHHeader Email Address ParsingEPSS 0.2%CVE-2026-29141HIGHBounded Subject Tag SanitizationEPSS 0.2%CVE-2026-29144HIGHUnicode Subject TagsEPSS 0.2%CVE-2026-29137MEDIUMLong Subject UntaggingEPSS 0.2%CVE-2026-2746MEDIUMMissing PGP Signature TagEPSS 0.2%CVE-2026-9592HIGHSensitive Information Disclosure in HTTP headerEPSS 0.2%