An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:NSecomea Gatemanager 4250
HWSecomeaall versionsSecomea Gatemanager 4250 Firmware
OSSecomea< 9.0iSecomea Gatemanager 4260
HWSecomeaall versionsSecomea Gatemanager 4260 Firmware
OSSecomea< 9.0iSecomea Gatemanager 8250
HWSecomeaall versionsSecomea Gatemanager 8250 Firmware
OSSecomea< 9.2cSecomea Gatemanager 9250
HWSecomeaall versionsSecomea Gatemanager 9250 Firmware
OSSecomea< 9.0i
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
IDOR
Related vulnerabilities
CVE-2020-29026CRITICAL9.0PL ✓same product
Path Traversal w Secomea GateManager — odczyt i zapis dowolnych plików
CVE-2020-14510CRITICAL9.8PL ✓same product
Secomea GateManager — zakodowane dane logowania do telnet umożliwiające RCE jako root
CVE-2020-14500CRITICAL10.0PL ✓same product
Przepełnienie bufora w Secomea GateManager — nadpisanie dowolnych danych
CVE-2022-25787HIGH7.5same product
Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allo...
CVE-2020-29032HIGH8.4same product
Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authent...