Secomea SiteManager是丹麦 (Secomea)公司的一个应用软件。提供一个工业设备远程维护功能。 Secomea SiteManager 9.7 之前的所有版本存在安全漏洞,该漏洞源于 SiteManager 中基于堆栈的缓冲区溢出漏洞允许登录或本地用户导致任意代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Secomea | SiteManager | all ~ 9.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-25784 | 9.1 CRITICAL | User controllable HTML element attribute (potential XSS) |
| CVE-2022-25787 | 7.5 HIGH | GTA URLs issued by LMM WEB API may leak information |
| CVE-2021-32010 | 5.6 MEDIUM | Clients may connect to a GateManager with TLS 1.0 |
| CVE-2022-25782 | 5.4 MEDIUM | Insufficient privilege checks on object access and updates. |
| CVE-2022-25786 | 4.9 MEDIUM | GateManager debug interface is included in production builds |
| CVE-2022-25779 | 4.3 MEDIUM | Insufficient scope checks allows adding unrelated audit log entries |
| CVE-2022-25780 | 4.3 MEDIUM | Information leak via device availability query function |
| CVE-2022-25783 | 4.3 MEDIUM | Hacking attempts from logged-in users are not properly logged by GM |
| CVE-2022-25778 | 4.2 MEDIUM | Unload handlers may unintentionally defeat CSRF guards |
| CVE-2022-25781 | 4.2 MEDIUM | Reflected XSS issues in GateManager |
No comments yet