CyberRota Analysis
AI-GeneratedThe SEPPmail Secure Email Gateway prior to version 15.0.6 is vulnerable due to improper validation of deserialized data in a privileged REST import workflow. This flaw allows an attacker with a valid API token to execute arbitrary commands with "nobody" privileges, potentially compromising the system's integrity. Organizations using this email gateway should prioritize remediation to mitigate the risk of unauthorized command execution.
Original NVD Description
SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.