CVE-2022-38123
- EPSS 0.75%
- Veröffentlicht 06.12.2022 16:15:10
- Zuletzt bearbeitet 21.11.2024 07:15:50
Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface. This issue affects: Secomea GateManager versions prior to 10.0.
CVE-2022-25786
- EPSS 0.71%
- Veröffentlicht 04.05.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:52:59
Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information. This issue affects: GateManager all versions prior to 9.7.
CVE-2021-32009
- EPSS 0.5%
- Veröffentlicht 11.03.2022 18:15:13
- Zuletzt bearbeitet 21.11.2024 06:06:42
Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject javascript in browser session. This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions.
CVE-2021-32006
- EPSS 0.64%
- Veröffentlicht 10.03.2022 17:42:13
- Zuletzt bearbeitet 21.11.2024 06:06:42
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logged in LinkManager user to access stored SiteManager backup files.
CVE-2021-32008
- EPSS 1%
- Veröffentlicht 04.03.2022 22:15:18
- Zuletzt bearbeitet 21.11.2024 06:06:42
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.