Page 5 of 34 results (0.005 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute malicious code. This issue affects: Secomea GateManager All versions prior to 9.4. Una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) en la GUI web de Secomea GateManager, permite a un atacante ejecutar código malicioso. Este problema afecta a: Secomea GateManager Todas las versiones anteriores a 9.4 • https://www.secomea.com/support/cybersecurity-advisory • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 6.3EPSS: 0%CPEs: 1EXPL: 0

Cross-site Scripting (XSS) vulnerability in web GUI of Secomea GateManager allows an attacker to inject arbitrary javascript code. This issue affects: Secomea GateManager all versions prior to 9.4. Una vulnerabilidad de tipo Cross-Site Scripting (XSS) en la GUI web de Secomea GateManager, permite a un atacante inyectar código javascript arbitrario. Este problema afecta a: Secomea GateManager todas las versiones anteriores a 9.4 • https://www.secomea.com/support/cybersecurity-advisory • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.3EPSS: 0%CPEs: 1EXPL: 0

Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker to execute arbitrary javascript code. This issue affects: Secomea GateManager all versions prior to 9.4. Una vulnerabilidad de Comprobación Inapropiada de la Entrada y de tipo Cross-site Scripting (XSS) en la GUI web de Secomea GateManager, permite a un atacante ejecutar código javascript arbitrario. Este problema afecta a: Secomea GateManager todas las versiones anteriores a 9.4 • https://www.secomea.com/support/cybersecurity-advisory • CWE-20: Improper Input Validation CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.4EPSS: 0%CPEs: 2EXPL: 0

Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious code on server. This issue affects: Secomea GateManager all versions prior to 9.4.621054022 Una vulnerabilidad de Carga de Código Sin Comprobación de integridad en el archivo de firmware de Secomea GateManager, permite a un atacante autenticado ejecutar código malicioso en el servidor. Este problema afecta a: Secomea GateManager todas las versiones anteriores a 9.4.621054022 • https://www.secomea.com/support/cybersecurity-advisory/#3737 https://www.tenable.com/security/research/tra-2021-06 • CWE-434: Unrestricted Upload of File with Dangerous Type CWE-494: Download of Code Without Integrity Check •

CVSS: 4.9EPSS: 0%CPEs: 8EXPL: 0

Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's computer when opened in a spreadsheet program (like Excel). This issue affects: Secomea GateManager all versions prior to 9.3. Una Codificación o Escape Inapropiado de la Salida de CSV Report Generator de Secomea GateManager, permite a un administrador autenticado generar un archivo CSV que puede ejecutar comandos arbitrarios en la computadora de la víctima cuando se abre en un programa de hoja de cálculo (como Excel). Este problema afecta: Secomea GateManager todas las versiones anteriores a 9.3 • https://www.secomea.com/support/cybersecurity-advisory https://www.secomea.com/support/cybersecurity-advisory/#2418 • CWE-116: Improper Encoding or Escaping of Output •