8.1

CVE-2021-32010

Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks. This issue affects: Secomea SiteManager All versions prior to 9.7. Secomea LinkManager versions prior to 9.7. Secomea GateManager versions prior to 9.7.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SecomeaSitemanager 1129 Firmware Version < 9.7.622134021
   SecomeaSitemanager 1129 Version-
SecomeaSitemanager 1139 Firmware Version < 9.7.622134021
   SecomeaSitemanager 1139 Version-
SecomeaSitemanager 1149 Firmware Version < 9.7.622134021
   SecomeaSitemanager 1149 Version-
SecomeaSitemanager 3329 Firmware Version < 9.7.622134021
   SecomeaSitemanager 3329 Version-
SecomeaSitemanager 3339 Firmware Version < 9.7.622134021
   SecomeaSitemanager 3339 Version-
SecomeaSitemanager 3349 Firmware Version < 9.7.622134021
   SecomeaSitemanager 3349 Version-
SecomeaSitemanager 3529 Firmware Version < 9.7.622134021
   SecomeaSitemanager 3529 Version-
SecomeaSitemanager 3539 Firmware Version < 9.7.622134021
   SecomeaSitemanager 3539 Version-
SecomeaSitemanager 3549 Firmware Version < 9.7.622134021
   SecomeaSitemanager 3549 Version-
SecomeaLinkmanager Version < 9.7.622134021
SecomeaGatemanager 4250 Firmware Version < 9.7.622134021
   SecomeaGatemanager 4250 Version-
SecomeaGatemanager 4260 Firmware Version < 9.7.622134021
   SecomeaGatemanager 4260 Version-
SecomeaGatemanager 8250 Firmware Version < 9.7.622134021
   SecomeaGatemanager 8250 Version-
SecomeaGatemanager 9250 Firmware Version < 9.7.622134021
   SecomeaGatemanager 9250 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.288
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
VulnerabilityReporting@secomea.com 5.6 2.2 3.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.