Secomea GateManager是丹麦Secomea公司的一款远程访问服务器产品。 Secomea GateManager 9.7 之前版本存在安全漏洞,该漏洞源于 Secomea GateManager 的 Web UI 中的权限处理不当,允许登录用户访问和更新权限信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Secomea | GateManager | unspecified ~ 9.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-25784 | 9.1 CRITICAL | User controllable HTML element attribute (potential XSS) |
| CVE-2022-25787 | 7.5 HIGH | GTA URLs issued by LMM WEB API may leak information |
| CVE-2022-25785 | 6.6 MEDIUM | Buffer overrun |
| CVE-2021-32010 | 5.6 MEDIUM | Clients may connect to a GateManager with TLS 1.0 |
| CVE-2022-25786 | 4.9 MEDIUM | GateManager debug interface is included in production builds |
| CVE-2022-25779 | 4.3 MEDIUM | Insufficient scope checks allows adding unrelated audit log entries |
| CVE-2022-25780 | 4.3 MEDIUM | Information leak via device availability query function |
| CVE-2022-25783 | 4.3 MEDIUM | Hacking attempts from logged-in users are not properly logged by GM |
| CVE-2022-25778 | 4.2 MEDIUM | Unload handlers may unintentionally defeat CSRF guards |
| CVE-2022-25781 | 4.2 MEDIUM | Reflected XSS issues in GateManager |
No comments yet