VendorsSecomeagatemanager_8250any version
Vulnerabilities

Secomea GatemManager 8250 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2020-14510
OFF-BY-ONE ERROR CWE-193
Published 2020-08-25 · Modified
10.0EPSS 0.025
CVE-2020-14500
IMPROPER NEUTRALIZATION OF NULL BYTE OR NUL CHARACTER CWE-158
Published 2020-08-25 · Modified
10.0EPSS 0.017
CVE-2020-14508
OFF-BY-ONE ERROR CWE-193
Published 2020-08-25 · Modified
9.8EPSS 0.020
CVE-2020-29026
A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with administrative permissions to read and write arbitrary files in the Linux file system. This issue affects: GateManager all versions prior to 9.2c.
Published 2021-02-15 · Modified
9.0EPSS 0.015
CVE-2022-25778
Unload handlers may unintentionally defeat CSRF guards
Published 2022-05-04 · Modified
8.8EPSS 0.003
CVE-2020-29032
Add integrity check of GateManager firmware
Published 2021-03-05 · Modified
8.4EPSS 0.005
CVE-2020-14512
USE OF PASSWORD HASH WITH INSUFFICIENT COMPUTATIONAL EFFORT CWE-916
Published 2020-08-25 · Modified
8.1EPSS 0.008
CVE-2020-29031
Insecure Direct Object Reference in GateManager WebUI can cause privilege escalation
Published 2021-02-15 · Modified
8.1EPSS 0.007
CVE-2021-32010
Clients may connect to a GateManager with TLS 1.0
Published 2022-05-04 · Modified
8.1EPSS 0.002
CVE-2022-25787
GTA URLs issued by LMM WEB API may leak information
Published 2022-05-04 · Modified
7.5EPSS 0.002
CVE-2022-25781
Reflected XSS issues in GateManager
Published 2022-05-04 · Modified
6.1EPSS 0.005
CVE-2022-25782
Insufficient privilege checks on object access and updates.
Published 2022-05-04 · Modified
5.5EPSS 0.005
CVE-2020-29022
Host Header Injection allowing web cache poisoning attacks
Published 2021-02-16 · Modified
5.3EPSS 0.008
CVE-2021-32004
GateManager does not enforce strict hostname matching for WEB server
Published 2021-11-22 · Modified
5.3EPSS 0.006
CVE-2020-29024
Missing HtppOnly and Secure flags
Published 2021-02-16 · Modified
5.3EPSS 0.005
CVE-2020-29023
CSV Formula Injection possible due to improper fields escaping in GateManager
Published 2021-02-16 · Modified
4.9EPSS 0.005
CVE-2020-29021
Scripting tag chars < > not filtered in input fields could cause Cross-Site Scripting (XSS)
Published 2021-02-08 · Modified
4.8EPSS 0.006
CVE-2022-25780
Information leak via device availability query function
Published 2022-05-04 · Modified
4.3EPSS 0.006
CVE-2022-25783
Hacking attempts from logged-in users are not properly logged by GM
Published 2022-05-04 · Modified
4.3EPSS 0.006
CVE-2022-25779
Insufficient scope checks allows adding unrelated audit log entries
Published 2022-05-04 · Modified
4.3EPSS 0.006