Secomea GateManager是丹麦Secomea公司的一款远程访问服务器产品。 Secomea GateManager 9.7 之前版本存在安全漏洞,该漏洞源于 Secomea GateManager 的 Web UI 中的信息暴露,允许登录用户查询自己范围之外的设备。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Secomea | GateManager | unspecified ~ 9.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-25784 | 9.1 CRITICAL | User controllable HTML element attribute (potential XSS) |
| CVE-2022-25787 | 7.5 HIGH | GTA URLs issued by LMM WEB API may leak information |
| CVE-2022-25785 | 6.6 MEDIUM | Buffer overrun |
| CVE-2021-32010 | 5.6 MEDIUM | Clients may connect to a GateManager with TLS 1.0 |
| CVE-2022-25782 | 5.4 MEDIUM | Insufficient privilege checks on object access and updates. |
| CVE-2022-25786 | 4.9 MEDIUM | GateManager debug interface is included in production builds |
| CVE-2022-25779 | 4.3 MEDIUM | Insufficient scope checks allows adding unrelated audit log entries |
| CVE-2022-25783 | 4.3 MEDIUM | Hacking attempts from logged-in users are not properly logged by GM |
| CVE-2022-25778 | 4.2 MEDIUM | Unload handlers may unintentionally defeat CSRF guards |
| CVE-2022-25781 | 4.2 MEDIUM | Reflected XSS issues in GateManager |
No comments yet