CVE-2020-29026
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Exploitability: 1.2 / Impact: 5.2
Source: NVD
Description
A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with administrative permissions to read and write arbitrary files in the Linux file system. This issue affects: GateManager all versions prior to 9.2c.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.2c |
| Running on/with | Platform Versions |
|---|---|
Secomea Gatemanager 8250 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.0i |
| Running on/with | Platform Versions |
|---|---|
Secomea Gatemanager 4250 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.0i |
| Running on/with | Platform Versions |
|---|---|
Secomea Gatemanager 4260 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.0i |
| Running on/with | Platform Versions |
|---|---|
Secomea Gatemanager 9250 | All versions |
References (2)
Source: VulnerabilityReporting@secomea.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.