An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:NSecomea Gatemanager 4250
HWSecomeawszystkie wersjeSecomea Gatemanager 4250 Firmware
OSSecomea< 9.0iSecomea Gatemanager 4260
HWSecomeawszystkie wersjeSecomea Gatemanager 4260 Firmware
OSSecomea< 9.0iSecomea Gatemanager 8250
HWSecomeawszystkie wersjeSecomea Gatemanager 8250 Firmware
OSSecomea< 9.2cSecomea Gatemanager 9250
HWSecomeawszystkie wersjeSecomea Gatemanager 9250 Firmware
OSSecomea< 9.0i
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
IDOR
Powiązane podatności
CVE-2020-29026CRITICAL9.0PL ✓ten sam produkt
Path Traversal w Secomea GateManager — odczyt i zapis dowolnych plików
CVE-2020-14510CRITICAL9.8PL ✓ten sam produkt
Secomea GateManager — zakodowane dane logowania do telnet umożliwiające RCE jako root
CVE-2020-14500CRITICAL10.0PL ✓ten sam produkt
Przepełnienie bufora w Secomea GateManager — nadpisanie dowolnych danych
CVE-2022-25787HIGH7.5ten sam produkt
Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allo...
CVE-2020-29032HIGH8.4ten sam produkt
Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authent...