CVE-2022-25779
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD
Description
Logging of Excessive Data vulnerability in audit log of Secomea GateManager allows logged in user to write text entries in audit log. This issue affects: Secomea GateManager versions prior to 9.7.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.7.622134021 |
| Running on/with | Platform Versions |
|---|---|
Secomea Gatemanager 4250 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.7.622134021 |
| Running on/with | Platform Versions |
|---|---|
Secomea Gatemanager 4260 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.7.622134021 |
| Running on/with | Platform Versions |
|---|---|
Secomea Gatemanager 8250 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.7.622134021 |
| Running on/with | Platform Versions |
|---|---|
Secomea Gatemanager 9250 | All versions |
Related CWEs
CWE-400
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CWE-779
Logging of Excessive Data
The product logs too much information, making log files hard to process and possibly hindering recovery efforts or forensic analysis after an attack.
References (2)
Source: VulnerabilityReporting@secomea.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.