CVE-2025-25235 – Omnissa Secure Email Gateway (SEG) SSRF

The following table lists the changes that have been made to the
CVE-2025-25235 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by de5a6978-88fe-4c27-a7df-d0d5b52d5b52

    Aug. 11, 2025

    Action Type Old Value New Value
    Added Description Server-Side Request Forgery (SSRF) in Omnissa Secure Email Gateway (SEG) in SEG prior to 2.32 running on Windows and SEG prior to 2503 running on UAG allows routing of network traffic such as HTTP requests to internal networks.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
    Added CWE CWE-918
    Added Reference https://www.omnissa.com/omsa-2025-0003/
Share the Post:

Related Posts