![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-25787 – GTA URLs issued by LMM WEB API may leak information
https://notcve.org/view.php?id=CVE-2022-25787
04 May 2022 — Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack connection. This issue affects: Secomea GateManager all versions prior to 9.7. Una Exposición de Información Mediante Cadenas de Consulta en la Petición GET es una vulnerabilidad en la API LMM de Secomea GateManager que permite al administrador del sistema secuestrar la conexión. Este problema afecta a: Secomea GateManager todas las versiones anteriores a 9.7 • https://www.secomea.com/support/cybersecurity-advisory • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-598: Use of GET Request Method With Sensitive Query Strings •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-25783 – Hacking attempts from logged-in users are not properly logged by GM
https://notcve.org/view.php?id=CVE-2022-25783
04 May 2022 — Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries without logging. This issue affects: Secomea GateManager versions prior to 9.7. Una vulnerabilidad de registro insuficiente en el servidor web de Secomea GateManager permite al usuario que ha iniciado la sesión realizar consultas indebidas sin registrarlas. Este problema afecta a: Las versiones de Secomea GateManager anteriores a la 9.7 • https://www.secomea.com/support/cybersecurity-advisory • CWE-778: Insufficient Logging •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-25782 – Insufficient privilege checks on object access and updates.
https://notcve.org/view.php?id=CVE-2022-25782
04 May 2022 — Improper Handling of Insufficient Privileges vulnerability in Web UI of Secomea GateManager allows logged in user to access and update privileged information. This issue affects: Secomea GateManager versions prior to 9.7. Una vulnerabilidad de Manejo Inapropiado de Privilegios en la Interfaz de Usuario Web de Secomea GateManager permite al usuario que ha iniciado la sesión acceder a información privilegiada y actualizarla. Este problema afecta a: Las versiones de Secomea GateManager anteriores a 9.7 • https://www.secomea.com/support/cybersecurity-advisory • CWE-269: Improper Privilege Management CWE-274: Improper Handling of Insufficient Privileges •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-25781 – Reflected XSS issues in GateManager
https://notcve.org/view.php?id=CVE-2022-25781
04 May 2022 — Cross-site Scripting (XSS) vulnerability in Web UI of Secomea GateManager allows phishing attacker to inject javascript or html into logged in user session. Una vulnerabilidad de tipo Cross-site Scripting (XSS) en la Interfaz de Usuario Web de Secomea GateManager permite a un atacante de phishing inyectar javascript o html en la sesión del usuario conectado • https://www.secomea.com/support/cybersecurity-advisory • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-25780 – Information leak via device availability query function
https://notcve.org/view.php?id=CVE-2022-25780
04 May 2022 — Information Exposure vulnerability in web UI of Secomea GateManager allows logged in user to query devices outside own scope. Una vulnerabilidad de exposición de información en la Interfaz de Usuario Web de Secomea GateManager permite al usuario que ha iniciado la sesión consultar dispositivos fuera de su ámbito • https://www.secomea.com/support/cybersecurity-advisory • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-25779 – Insufficient scope checks allows adding unrelated audit log entries
https://notcve.org/view.php?id=CVE-2022-25779
04 May 2022 — Logging of Excessive Data vulnerability in audit log of Secomea GateManager allows logged in user to write text entries in audit log. This issue affects: Secomea GateManager versions prior to 9.7. Una vulnerabilidad de registro de datos excesivos en el registro de auditoría de Secomea GateManager permite al usuario que ha iniciado la sesión escribir entradas de texto en el registro de auditoría. Este problema afecta a: Las versiones de Secomea GateManager anteriores a 9.7 • https://www.secomea.com/support/cybersecurity-advisory • CWE-400: Uncontrolled Resource Consumption CWE-779: Logging of Excessive Data •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-25778 – Unload handlers may unintentionally defeat CSRF guards
https://notcve.org/view.php?id=CVE-2022-25778
04 May 2022 — Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user session. Una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) en la Interfaz de Usuario Web de Secomea GateManager permite a un atacante de phishing emitir una petición de obtención en la sesión del usuario conectado • https://www.secomea.com/support/cybersecurity-advisory • CWE-352: Cross-Site Request Forgery (CSRF) •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-32010 – Clients may connect to a GateManager with TLS 1.0
https://notcve.org/view.php?id=CVE-2021-32010
04 May 2022 — Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks. This issue affects: Secomea SiteManager All versions prior to 9.7. Secomea LinkManager versions prior to 9.7. Secomea GateManager versions prior to 9.7. Una vulnerabilidad de la fuerza de encriptación inapropiada en la pila TLS de Secomea SiteManager, LinkManager y GateManager puede facilitar ataques de tipo man in the middle. • https://www.secomea.com/support/cybersecurity-advisory • CWE-326: Inadequate Encryption Strength •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-29031 – Insecure Direct Object Reference in GateManager WebUI can cause privilege escalation
https://notcve.org/view.php?id=CVE-2020-29031
15 Feb 2021 — An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c Se presenta una vulnerabilidad de Referencia Directa a Objetos No Segura en la Interfaz de Usuario Web de GateManager que permite a un atacante autenticado restablecer la contraseña de cualquier usuario en su dominio o subdomini... • https://www.secomea.com/support/cybersecurity-advisory/#2920 • CWE-269: Improper Privilege Management CWE-280: Improper Handling of Insufficient Permissions or Privileges •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-29026
https://notcve.org/view.php?id=CVE-2020-29026
15 Feb 2021 — A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with administrative permissions to read and write arbitrary files in the Linux file system. This issue affects: GateManager all versions prior to 9.2c. Se presenta una vulnerabilidad de salto de directorio en la función file upload del GateManager que permite a un atacante autenticado con permisos administrativos leer y escribir archivos arbitrarios en el sistema de archivos de Lin... • https://www.secomea.com/support/cybersecurity-advisory/#2918 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •