CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2020-29026

CVSS 9.0v3.1pub. 2021-02-15upd. 2024-11-21

A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with administrative permissions to read and write arbitrary files in the Linux file system. This issue affects: GateManager all versions prior to 9.2c.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
  • Secomea Gatemanager 4250

    HW
    Secomea
    all versions
  • Secomea Gatemanager 4250 Firmware

    OS
    Secomea
    < 9.0i
  • Secomea Gatemanager 4260

    HW
    Secomea
    all versions
  • Secomea Gatemanager 4260 Firmware

    OS
    Secomea
    < 9.0i
  • Secomea Gatemanager 8250

    HW
    Secomea
    all versions
  • Secomea Gatemanager 8250 Firmware

    OS
    Secomea
    < 9.2c
  • Secomea Gatemanager 9250

    HW
    Secomea
    all versions
  • Secomea Gatemanager 9250 Firmware

    OS
    Secomea
    < 9.0i
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2020-14500CRITICAL10.0PL ✓same product

Przepełnienie bufora w Secomea GateManager — nadpisanie dowolnych danych

CVE-2020-14510CRITICAL9.8PL ✓same product

Secomea GateManager — zakodowane dane logowania do telnet umożliwiające RCE jako root

CVE-2022-25787HIGH7.5same product

Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allo...

CVE-2020-29032HIGH8.4same product

Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authent...

CVE-2020-29031HIGH7.1same product

An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an auth...