4.3
CVE-2022-25779
- EPSS 0.51%
- Veröffentlicht 04.05.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:52:58
- Quelle VulnerabilityReporting@secomea
- CVE-Watchlists
- Unerledigt
Insufficient scope checks allows adding unrelated audit log entries
Logging of Excessive Data vulnerability in audit log of Secomea GateManager allows logged in user to write text entries in audit log. This issue affects: Secomea GateManager versions prior to 9.7.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Secomea ≫ Gatemanager 4250 Firmware Version < 9.7.622134021
Secomea ≫ Gatemanager 4260 Firmware Version < 9.7.622134021
Secomea ≫ Gatemanager 8250 Firmware Version < 9.7.622134021
Secomea ≫ Gatemanager 9250 Firmware Version < 9.7.622134021
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.51% | 0.391 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:N
|
| VulnerabilityReporting@secomea.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CWE-779 Logging of Excessive Data
The product logs too much information, making log files hard to process and possibly hindering recovery efforts or forensic analysis after an attack.
https://www.secomea.com/support/cybersecurity-advisory/