VendorsSecomeagatemanager_9250any version
Vulnerabilities

Secomea GateManager 9250 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2020-29026
A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with administrative permissions to read and write arbitrary files in the Linux file system. This issue affects: GateManager all versions prior to 9.2c.
Published 2021-02-15 · Modified
9.0EPSS 0.015
CVE-2022-25778
Unload handlers may unintentionally defeat CSRF guards
Published 2022-05-04 · Modified
8.8EPSS 0.003
CVE-2020-29031
Insecure Direct Object Reference in GateManager WebUI can cause privilege escalation
Published 2021-02-15 · Modified
8.1EPSS 0.007
CVE-2021-32010
Clients may connect to a GateManager with TLS 1.0
Published 2022-05-04 · Modified
8.1EPSS 0.002
CVE-2022-25787
GTA URLs issued by LMM WEB API may leak information
Published 2022-05-04 · Modified
7.5EPSS 0.002
CVE-2022-25781
Reflected XSS issues in GateManager
Published 2022-05-04 · Modified
6.1EPSS 0.005
CVE-2022-25782
Insufficient privilege checks on object access and updates.
Published 2022-05-04 · Modified
5.5EPSS 0.005
CVE-2020-29022
Host Header Injection allowing web cache poisoning attacks
Published 2021-02-16 · Modified
5.3EPSS 0.008
CVE-2020-29024
Missing HtppOnly and Secure flags
Published 2021-02-16 · Modified
5.3EPSS 0.005
CVE-2020-29023
CSV Formula Injection possible due to improper fields escaping in GateManager
Published 2021-02-16 · Modified
4.9EPSS 0.005
CVE-2020-29021
Scripting tag chars < > not filtered in input fields could cause Cross-Site Scripting (XSS)
Published 2021-02-08 · Modified
4.8EPSS 0.006
CVE-2022-25780
Information leak via device availability query function
Published 2022-05-04 · Modified
4.3EPSS 0.006
CVE-2022-25783
Hacking attempts from logged-in users are not properly logged by GM
Published 2022-05-04 · Modified
4.3EPSS 0.006
CVE-2022-25779
Insufficient scope checks allows adding unrelated audit log entries
Published 2022-05-04 · Modified
4.3EPSS 0.006