I figured that a host connected to the Orange interface can set its IP to something in the Green network range and get access to everything on the Green network, exactly like if it was connected to the Green interface.
Without boring you with details the machine in the DMZ was a VM and I thought the physical NIC was passed through from the host but it was in fact sharing a bridge with the host.