CyberRota Analysis
AI-GeneratedSEPPmail Secure Email Gateway versions prior to 15.0.7 are vulnerable due to the creation of a fully privileged session before the completion of multi-factor authentication enrollment. This flaw allows an attacker with the password of an unenrolled account to bypass the second authentication factor, potentially leading to unauthorized access to sensitive functionalities. Organizations using this email gateway should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.