4.3

CVE-2022-25779

Insufficient scope checks allows adding unrelated audit log entries

Logging of Excessive Data vulnerability in audit log of Secomea GateManager allows logged in user to write text entries in audit log. This issue affects: Secomea GateManager versions prior to 9.7.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SecomeaGatemanager 4250 Firmware Version < 9.7.622134021
   SecomeaGatemanager 4250 Version-
SecomeaGatemanager 4260 Firmware Version < 9.7.622134021
   SecomeaGatemanager 4260 Version-
SecomeaGatemanager 8250 Firmware Version < 9.7.622134021
   SecomeaGatemanager 8250 Version-
SecomeaGatemanager 9250 Firmware Version < 9.7.622134021
   SecomeaGatemanager 9250 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.415
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
VulnerabilityReporting@secomea.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

CWE-779 Logging of Excessive Data

The product logs too much information, making log files hard to process and possibly hindering recovery efforts or forensic analysis after an attack.

https://www.secomea.com/support/cybersecurity-advisory/
Vendor Advisory