CVE-2020-29028 – Reflected XSS issues
https://notcve.org/view.php?id=CVE-2020-29028
Cross-site Scripting (XSS) vulnerability in web GUI of Secomea GateManager allows an attacker to inject arbitrary javascript code. This issue affects: Secomea GateManager all versions prior to 9.4. Una vulnerabilidad de tipo Cross-Site Scripting (XSS) en la GUI web de Secomea GateManager, permite a un atacante inyectar código javascript arbitrario. Este problema afecta a: Secomea GateManager todas las versiones anteriores a 9.4 • https://www.secomea.com/support/cybersecurity-advisory • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-29029 – XSS issue due to insufficient sanitization of input field
https://notcve.org/view.php?id=CVE-2020-29029
Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker to execute arbitrary javascript code. This issue affects: Secomea GateManager all versions prior to 9.4. Una vulnerabilidad de Comprobación Inapropiada de la Entrada y de tipo Cross-site Scripting (XSS) en la GUI web de Secomea GateManager, permite a un atacante ejecutar código javascript arbitrario. Este problema afecta a: Secomea GateManager todas las versiones anteriores a 9.4 • https://www.secomea.com/support/cybersecurity-advisory • CWE-20: Improper Input Validation CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-29032 – Add integrity check of GateManager firmware
https://notcve.org/view.php?id=CVE-2020-29032
Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious code on server. This issue affects: Secomea GateManager all versions prior to 9.4.621054022 Una vulnerabilidad de Carga de Código Sin Comprobación de integridad en el archivo de firmware de Secomea GateManager, permite a un atacante autenticado ejecutar código malicioso en el servidor. Este problema afecta a: Secomea GateManager todas las versiones anteriores a 9.4.621054022 • https://www.secomea.com/support/cybersecurity-advisory/#3737 https://www.tenable.com/security/research/tra-2021-06 • CWE-434: Unrestricted Upload of File with Dangerous Type CWE-494: Download of Code Without Integrity Check •
CVE-2020-29023 – CSV Formula Injection possible due to improper fields escaping in GateManager
https://notcve.org/view.php?id=CVE-2020-29023
Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's computer when opened in a spreadsheet program (like Excel). This issue affects: Secomea GateManager all versions prior to 9.3. Una Codificación o Escape Inapropiado de la Salida de CSV Report Generator de Secomea GateManager, permite a un administrador autenticado generar un archivo CSV que puede ejecutar comandos arbitrarios en la computadora de la víctima cuando se abre en un programa de hoja de cálculo (como Excel). Este problema afecta: Secomea GateManager todas las versiones anteriores a 9.3 • https://www.secomea.com/support/cybersecurity-advisory https://www.secomea.com/support/cybersecurity-advisory/#2418 • CWE-116: Improper Encoding or Escaping of Output •
CVE-2020-29022 – Host Header Injection allowing web cache poisoning attacks
https://notcve.org/view.php?id=CVE-2020-29022
Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior to 9.3 Un fallo en la saneamiento del valor del encabezado del host en la salida del servidor web GateManager, podría permitir a un atacante conducir ataques de envenenamiento de la caché web. Este problema afecta a Secomea GateManager todas las versiones anteriores a 9.3 • https://www.secomea.com/support/cybersecurity-advisory/#2923 • CWE-159: Improper Handling of Invalid Use of Special Elements •