← Back

CVE-2020-29031

nvd nist
Published: Feb 15, 2021Modified: Jun 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD

Description

An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c

Affected (4)

4 products
Gatemanager 8250 Firmware
Gatemanager 4250 Firmware
Gatemanager 4260 Firmware
Gatemanager 9250 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 9.2c
Running on/withPlatform Versions
Secomea
Gatemanager 8250
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 9.0i
Running on/withPlatform Versions
Secomea
Gatemanager 4250
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 9.0i
Running on/withPlatform Versions
Secomea
Gatemanager 4260
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 9.0i
Running on/withPlatform Versions
Secomea
Gatemanager 9250
All versions

References (2)

Source: VulnerabilityReporting@secomea.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.