CVE-2020-29031
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD
Description
An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.2c |
| Running on/with | Platform Versions |
|---|---|
Secomea Gatemanager 8250 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.0i |
| Running on/with | Platform Versions |
|---|---|
Secomea Gatemanager 4250 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.0i |
| Running on/with | Platform Versions |
|---|---|
Secomea Gatemanager 4260 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.0i |
| Running on/with | Platform Versions |
|---|---|
Secomea Gatemanager 9250 | All versions |
Related CWEs
CWE-269
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-280
Improper Handling of Insufficient Permissions or Privileges
The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.
References (2)
Source: VulnerabilityReporting@secomea.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.