HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2020-29031

CVSS 7.1v3.1pub. 2021-02-15upd. 2024-11-21

An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
  • Secomea Gatemanager 4250

    HW
    Secomea
    all versions
  • Secomea Gatemanager 4250 Firmware

    OS
    Secomea
    < 9.0i
  • Secomea Gatemanager 4260

    HW
    Secomea
    all versions
  • Secomea Gatemanager 4260 Firmware

    OS
    Secomea
    < 9.0i
  • Secomea Gatemanager 8250

    HW
    Secomea
    all versions
  • Secomea Gatemanager 8250 Firmware

    OS
    Secomea
    < 9.2c
  • Secomea Gatemanager 9250

    HW
    Secomea
    all versions
  • Secomea Gatemanager 9250 Firmware

    OS
    Secomea
    < 9.0i
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
IDOR
CWE
References

Related vulnerabilities

CVE-2020-29026CRITICAL9.0PL ✓same product

Path Traversal w Secomea GateManager — odczyt i zapis dowolnych plików

CVE-2020-14510CRITICAL9.8PL ✓same product

Secomea GateManager — zakodowane dane logowania do telnet umożliwiające RCE jako root

CVE-2020-14500CRITICAL10.0PL ✓same product

Przepełnienie bufora w Secomea GateManager — nadpisanie dowolnych danych

CVE-2022-25787HIGH7.5same product

Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allo...

CVE-2020-29032HIGH8.4same product

Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authent...