secomea 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。
過去の問題は主に vendor risk input validation and vendor risk csrf などに関し、一部は vendor impact unexpected behavior を招き、vendor surface software deployment and vendor surface production workloads 関連の場面に影響します。
掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2023-2912 | Use After Free vulnerability in Secomea SiteManager Embedded allows Obstruction. | [email protected] | 5.9 | 0.45% | 2023-07-17 | 2026-06-17 |
| CVE-2023-0317 | Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information. | [email protected] | 4.9 | 0.52% | 2023-04-19 | 2026-06-17 |
| CVE-2022-4308 | Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked. | [email protected] | 6.1 | 0.17% | 2023-04-19 | 2026-06-17 |
| CVE-2022-38125 | Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modules) allows Exploiting Trust in Client. | [email protected] | 2.9 | 0.16% | 2023-04-19 | 2026-06-17 |
| CVE-2022-38124 | Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner. | [email protected] | 5.7 | 0.51% | 2022-12-13 | 2026-06-17 |
| CVE-2022-2752 | A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. This issue affects: Secomea GateManager versions from 9.4 through 9.7. | [email protected] | 5.5 | 0.18% | 2022-12-09 | 2026-06-17 |
| CVE-2022-38123 | Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface. This issue affects: Secomea GateManager versions prior to 10.0. | [email protected] | 8.7 | 0.75% | 2022-12-06 | 2026-06-17 |
| CVE-2022-25786 | Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information. This issue affects: GateManager all versions prior to 9.7. | [email protected] | 4.9 | 0.67% | 2022-05-04 | 2026-06-17 |
| CVE-2022-25787 | Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack connection. This issue affects: Secomea GateManager all versions prior to 9.7. | [email protected] | 7.5 | 0.23% | 2022-05-04 | 2026-06-17 |
| CVE-2022-25785 | Stack-based Buffer Overflow vulnerability in SiteManager allows logged-in or local user to cause arbitrary code execution. This issue affects: Secomea SiteManager all versions prior to 9.7. | [email protected] | 6.6 | 0.90% | 2022-05-04 | 2026-06-17 |
| CVE-2022-25784 | Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue affects: Secomea SiteManager all versions prior to 9.7. | [email protected] | 9.1 | 0.56% | 2022-05-04 | 2026-06-17 |
| CVE-2022-25783 | Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries without logging. This issue affects: Secomea GateManager versions prior to 9.7. | [email protected] | 4.3 | 0.57% | 2022-05-04 | 2026-06-17 |
| CVE-2022-25782 | Improper Handling of Insufficient Privileges vulnerability in Web UI of Secomea GateManager allows logged in user to access and update privileged information. This issue affects: Secomea GateManager versions prior to 9.7. | [email protected] | 5.4 | 0.46% | 2022-05-04 | 2026-06-17 |
| CVE-2022-25781 | Cross-site Scripting (XSS) vulnerability in Web UI of Secomea GateManager allows phishing attacker to inject javascript or html into logged in user session. | [email protected] | 4.2 | 0.45% | 2022-05-04 | 2026-06-17 |
| CVE-2022-25780 | Information Exposure vulnerability in web UI of Secomea GateManager allows logged in user to query devices outside own scope. | [email protected] | 4.3 | 0.57% | 2022-05-04 | 2026-06-17 |
| CVE-2022-25779 | Logging of Excessive Data vulnerability in audit log of Secomea GateManager allows logged in user to write text entries in audit log. This issue affects: Secomea GateManager versions prior to 9.7. | [email protected] | 4.3 | 0.51% | 2022-05-04 | 2026-06-17 |
| CVE-2022-25778 | Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user session. | [email protected] | 4.2 | 0.26% | 2022-05-04 | 2026-06-17 |
| CVE-2021-32010 | Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks. This issue affects: Secomea SiteManager All versions prior to 9.7. Secomea LinkManager versions prior to 9.7. Secomea GateManager versions prior to 9.7. | [email protected] | 5.6 | 0.21% | 2022-05-04 | 2026-06-16 |
| CVE-2021-32009 | Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject javascript in browser session. This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. | [email protected] | 5.0 | 0.48% | 2022-03-11 | 2026-06-16 |
| CVE-2021-32006 | This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logged in LinkManager user to access stored SiteManager backup files. | [email protected] | 5.0 | 0.61% | 2022-03-10 | 2026-06-16 |