CVE-2025-25235

8.6

Omnissa · Secure Email Gateway (SEG)

A Server-Side Request Forgery vulnerability in Omnissa Secure Email Gateway allows unauthenticated attackers to route HTTP requests to internal network resources.

Executive summary

A critical Server-Side Request Forgery vulnerability in Omnissa Secure Email Gateway permits unauthorized access to internal network infrastructure, posing a significant risk to organizational security.

Vulnerability

This is a Server-Side Request Forgery (CWE-918) vulnerability occurring in the Secure Email Gateway. The flaw allows an unauthenticated attacker to force the server to perform requests to unintended internal destinations.

Business impact

The ability to perform SSRF allows attackers to bypass perimeter defenses and interact with internal services that are not exposed to the internet. This could lead to the exposure of sensitive internal data or the mapping of private network topologies. Given the CVSS score of 8.6, this vulnerability represents a high risk to the confidentiality of internal systems and requires immediate attention to prevent lateral movement.

Remediation

Immediate Action: Administrators must upgrade Omnissa Secure Email Gateway to version 2.32 or later for Windows installations, or 2503 or later for UAG deployments, as specified in the vendor advisory.

Proactive Monitoring: Monitor network traffic logs for suspicious outbound HTTP requests originating from the Secure Email Gateway server, particularly those targeting internal IP ranges or private services.

Compensating Controls: Implement strict egress filtering on the firewall to restrict the Secure Email Gateway from initiating connections to unauthorized internal network segments.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this flaw and the potential for internal network reconnaissance necessitate immediate patching. Security teams should verify their current version of Omnissa Secure Email Gateway and apply the vendor-provided updates immediately to close this attack vector. Ensure that all affected systems are audited for signs of unauthorized access once the patch has been successfully applied.

More Omnissa CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Published in the daily brief high section
  4. Analyst report written

Sources