Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sitemanager Embedded HIGH 7.5
CVE-2023-2912

Use After Free vulnerability in Secomea SiteManager Embedded allows Obstruction.

Fix: 11.0+
Fix from $1,950 2023-07-17
Gatemanager HIGH 8.8
CVE-2022-4308

Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file i…

Fix: 10.0.622425017+
Fix from $1,950 2023-04-19
Sitemanager 3549 Firmware MEDIUM 5.5
CVE-2022-38125

Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modules) allows Exploiting Trust …

Fix: 10.0.622465022+
Fix from $1,600 2023-04-19
Sitemanager 1129 Firmware MEDIUM 6.5
CVE-2022-38124

Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.

Fix: 10.0.622425017+
Fix from $1,600 2022-12-13
Gatemanager HIGH 7.8
CVE-2022-2752

A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. …

Fix: after 9.7
Fix from $1,950 2022-12-09
Gatemanager HIGH 7.2
CVE-2022-38123

Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the Gat…

Fix: 10.0.622395010+
Fix from $1,950 2022-12-06
Gatemanager 4250 Firmware HIGH 8.8
CVE-2022-25778

Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user sess…

Fix: 9.7.622134021+
Fix from $1,950 2022-05-04
Sitemanager 1129 Firmware HIGH 7.2
CVE-2022-25785

Stack-based Buffer Overflow vulnerability in SiteManager allows logged-in or local user to cause arbitrary code execution. This issue affects: Secome…

Fix: 9.7.622134021+
Fix from $1,950 2022-05-04
Gatemanager 4250 Firmware MEDIUM 6.7
CVE-2022-25787

Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack conne…

Fix: 9.7.622134021+
Fix from $1,600 2022-05-04
Gatemanager 4250 Firmware MEDIUM 6.1
CVE-2022-25781

Cross-site Scripting (XSS) vulnerability in Web UI of Secomea GateManager allows phishing attacker to inject javascript or html into logged in user s…

Fix: 9.7.622134021+
Fix from $1,600 2022-05-04
Gatemanager 4250 Firmware MEDIUM 5.4
CVE-2022-25782

Improper Handling of Insufficient Privileges vulnerability in Web UI of Secomea GateManager allows logged in user to access and update privileged inf…

Fix: 9.7.622134021+
Fix from $1,600 2022-05-04
Sitemanager 1129 Firmware HIGH 8.1
CVE-2021-32010

Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks. …

Fix: 9.7.622134021+
Fix from $1,950 2022-05-04
Gatemanager MEDIUM 6.1
CVE-2021-32009

Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject javascript in browser session. Th…

Fix: after 9.6.621421014
Fix from $1,600 2022-03-11
Sitemanager 1129 Firmware MEDIUM 5.4
CVE-2021-32005

Cross-site Scripting (XSS) vulnerability in log view of Secomea SiteManager allows a logged in user to store javascript for later execution. This iss…

Fix: 9.6.621421014+
Fix from $1,600 2022-03-10
Gatemanager HIGH 8.7
CVE-2021-32008

This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allo…

Fix: after 9.6.621421014
Fix from $1,950 2022-03-04
Gatemanager 8250 Firmware MEDIUM 5.3
CVE-2021-32004

This issue affects: Secomea GateManager All versions prior to 9.6. Improper Check of host header in web server of Secomea GateManager allows attacker…

Fix: 9.6+
Fix from $1,600 2021-11-22
Sitemanager Firmware MEDIUM 5.5
CVE-2021-32003

Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is…

Fix: 9.5.621256022+
Fix from $1,600 2021-08-05
Gatemanager Firmware HIGH 8.8
CVE-2020-29030

Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute malicious code. This issue affects: S…

Fix: 9.4.621054022+
Fix from $1,950 2021-03-05
Sitemanager Firmware HIGH 7.2
CVE-2020-29020

Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the c…

Fix: 9.4.620527004+
Fix from $1,950 2021-03-05
Gatemanager Firmware MEDIUM 6.1
CVE-2020-29028

Cross-site Scripting (XSS) vulnerability in web GUI of Secomea GateManager allows an attacker to inject arbitrary javascript code. This issue affects…

Fix: 9.4.621054022+
Fix from $1,600 2021-03-05
Gatemanager Firmware MEDIUM 6.1
CVE-2020-29029

Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker to execute arbitrary javascr…

Fix: 9.4.62105402+
Fix from $1,600 2021-03-05
Gatemanager 8250 Firmware HIGH 7.2
CVE-2020-29032

Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious co…

Fix: 9.4.621054022+
Fix from $1,950 2021-03-05
Sitemanager Embedded MEDIUM 6.1
CVE-2020-29025

A vulnerability in SiteManager-Embedded (SM-E) Web server which may allow attacker to construct a URL that if visited by another application user, wi…

Fix: 9.2c+
Fix from $1,600 2021-02-16
Sitemanager 1129 Firmware MEDIUM 5.4
CVE-2020-29027

Cross-site Scripting (XSS) vulnerability in GUI of Secomea SiteManager could allow an attacker to cause an XSS Attack. This issue affects: Secomea Si…

Fix: 9.2c+
Fix from $1,600 2021-02-16
Gatemanager 4250 Firmware MEDIUM 5.3
CVE-2020-29022

Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This is…

Fix: 9.3+
Fix from $1,600 2021-02-16
Gatemanager 4250 Firmware MEDIUM 5.3
CVE-2020-29024

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in (GTA) GoToAppliance of Secomea GateManager could allow an attacker to g…

Fix: 9.3+
Fix from $1,600 2021-02-16
Gatemanager 8250 Firmware HIGH 8.1
CVE-2020-29031

An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the passwor…

Fix: 9.0i / 9.2c+
Fix from $1,950 2021-02-15
Gatemanager 8250 Firmware MEDIUM 6.5
CVE-2020-29026

A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with administrative p…

Fix: 9.0i / 9.2c+
Fix from $1,600 2021-02-15
Gatemanager 8250 Firmware CRITICAL 9.8
CVE-2020-14500

Secomea GateManager all versions prior to 9.2c, An attacker can send a negative value and overwrite arbitrary data.

Mitigation only
Fix from $2,300 2020-08-25
Gatemanager 8250 Firmware CRITICAL 9.8
CVE-2020-14508

GateManager versions prior to 9.2c, The affected product is vulnerable to an off-by-one error, which may allow an attacker to remotely execute arbitr…

Mitigation only
Fix from $2,300 2020-08-25