Secomea GateManager是丹麦Secomea公司的一款远程访问服务器产品。 Secomea GateManager 9.7 之前版本存在安全漏洞,该漏洞源于 Secomea GateManager 的 Web UI 中的跨站请求伪造 (CSRF) 漏洞允许网络钓鱼攻击者在登录的用户会话中发出请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Secomea | GateManager | unspecified ~ 9.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-25784 | 9.1 CRITICAL | User controllable HTML element attribute (potential XSS) |
| CVE-2022-25787 | 7.5 HIGH | GTA URLs issued by LMM WEB API may leak information |
| CVE-2022-25785 | 6.6 MEDIUM | Buffer overrun |
| CVE-2021-32010 | 5.6 MEDIUM | Clients may connect to a GateManager with TLS 1.0 |
| CVE-2022-25782 | 5.4 MEDIUM | Insufficient privilege checks on object access and updates. |
| CVE-2022-25786 | 4.9 MEDIUM | GateManager debug interface is included in production builds |
| CVE-2022-25779 | 4.3 MEDIUM | Insufficient scope checks allows adding unrelated audit log entries |
| CVE-2022-25780 | 4.3 MEDIUM | Information leak via device availability query function |
| CVE-2022-25783 | 4.3 MEDIUM | Hacking attempts from logged-in users are not properly logged by GM |
| CVE-2022-25781 | 4.2 MEDIUM | Reflected XSS issues in GateManager |
No comments yet