HIGH✓ PATCH🇬🇧 English

CVE-2020-29031

CVSS 7.1v3.1pub. 2021-02-15upd. 2024-11-21

An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
  • Secomea Gatemanager 4250

    HW
    Secomea
    wszystkie wersje
  • Secomea Gatemanager 4250 Firmware

    OS
    Secomea
    < 9.0i
  • Secomea Gatemanager 4260

    HW
    Secomea
    wszystkie wersje
  • Secomea Gatemanager 4260 Firmware

    OS
    Secomea
    < 9.0i
  • Secomea Gatemanager 8250

    HW
    Secomea
    wszystkie wersje
  • Secomea Gatemanager 8250 Firmware

    OS
    Secomea
    < 9.2c
  • Secomea Gatemanager 9250

    HW
    Secomea
    wszystkie wersje
  • Secomea Gatemanager 9250 Firmware

    OS
    Secomea
    < 9.0i
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
IDOR
CWE
Referencje

Powiązane podatności

CVE-2020-29026CRITICAL9.0PL ✓ten sam produkt

Path Traversal w Secomea GateManager — odczyt i zapis dowolnych plików

CVE-2020-14510CRITICAL9.8PL ✓ten sam produkt

Secomea GateManager — zakodowane dane logowania do telnet umożliwiające RCE jako root

CVE-2020-14500CRITICAL10.0PL ✓ten sam produkt

Przepełnienie bufora w Secomea GateManager — nadpisanie dowolnych danych

CVE-2022-25787HIGH7.5ten sam produkt

Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allo...

CVE-2020-29032HIGH8.4ten sam produkt

Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authent...