Aggregates CVE and security vulnerability intelligence across all secomea-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk input validation and vendor risk csrf and related problems; some flaws may lead to vendor impact unexpected behavior, affecting vendor surface software deployment scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-2912 | Use After Free vulnerability in Secomea SiteManager Embedded allows Obstruction. | [email protected] | 5.9 | 0.18% | 2023-07-17 | 2024-11-21 |
| CVE-2023-0317 | Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information. | [email protected] | 4.9 | 0.23% | 2023-04-19 | 2025-02-05 |
| CVE-2022-4308 | Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked. | [email protected] | 6.1 | 0.05% | 2023-04-19 | 2025-02-05 |
| CVE-2022-38125 | Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modules) allows Exploiting Trust in Client. | [email protected] | 2.9 | 0.06% | 2023-04-19 | 2025-02-05 |
| CVE-2022-38124 | Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner. | [email protected] | 5.7 | 0.31% | 2022-12-13 | 2024-11-21 |
| CVE-2022-2752 | A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. This issue affects: Secomea GateManager versions from 9.4 through 9.7. | [email protected] | 5.5 | 0.04% | 2022-12-09 | 2024-11-21 |
| CVE-2022-38123 | Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface. This issue affects: Secomea GateManager versions prior to 10.0. | [email protected] | 8.7 | 0.52% | 2022-12-06 | 2024-11-21 |
| CVE-2022-25786 | Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information. This issue affects: GateManager all versions prior to 9.7. | [email protected] | 4.9 | 0.32% | 2022-05-04 | 2024-11-21 |
| CVE-2022-25787 | Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack connection. This issue affects: Secomea GateManager all versions prior to 9.7. | [email protected] | 7.5 | 0.06% | 2022-05-04 | 2024-11-21 |
| CVE-2022-25785 | Stack-based Buffer Overflow vulnerability in SiteManager allows logged-in or local user to cause arbitrary code execution. This issue affects: Secomea SiteManager all versions prior to 9.7. | [email protected] | 6.6 | 1.13% | 2022-05-04 | 2024-11-21 |
| CVE-2022-25784 | Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue affects: Secomea SiteManager all versions prior to 9.7. | [email protected] | 9.1 | 0.43% | 2022-05-04 | 2024-11-21 |
| CVE-2022-25783 | Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries without logging. This issue affects: Secomea GateManager versions prior to 9.7. | [email protected] | 4.3 | 0.23% | 2022-05-04 | 2024-11-21 |
| CVE-2022-25782 | Improper Handling of Insufficient Privileges vulnerability in Web UI of Secomea GateManager allows logged in user to access and update privileged information. This issue affects: Secomea GateManager versions prior to 9.7. | [email protected] | 5.4 | 0.21% | 2022-05-04 | 2024-11-21 |
| CVE-2022-25781 | Cross-site Scripting (XSS) vulnerability in Web UI of Secomea GateManager allows phishing attacker to inject javascript or html into logged in user session. | [email protected] | 4.2 | 0.37% | 2022-05-04 | 2024-11-21 |
| CVE-2022-25780 | Information Exposure vulnerability in web UI of Secomea GateManager allows logged in user to query devices outside own scope. | [email protected] | 4.3 | 0.35% | 2022-05-04 | 2024-11-21 |
| CVE-2022-25779 | Logging of Excessive Data vulnerability in audit log of Secomea GateManager allows logged in user to write text entries in audit log. This issue affects: Secomea GateManager versions prior to 9.7. | [email protected] | 4.3 | 0.34% | 2022-05-04 | 2024-11-21 |
| CVE-2022-25778 | Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user session. | [email protected] | 4.2 | 0.17% | 2022-05-04 | 2024-11-21 |
| CVE-2021-32010 | Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks. This issue affects: Secomea SiteManager All versions prior to 9.7. Secomea LinkManager versions prior to 9.7. Secomea GateManager versions prior to 9.7. | [email protected] | 5.6 | 0.06% | 2022-05-04 | 2024-11-21 |
| CVE-2021-32009 | Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject javascript in browser session. This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. | [email protected] | 5.0 | 0.32% | 2022-03-11 | 2024-11-21 |
| CVE-2021-32006 | This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logged in LinkManager user to access stored SiteManager backup files. | [email protected] | 5.0 | 0.15% | 2022-03-10 | 2024-11-21 |