Secomea
secomea
42 CVEs • 38 products
Products (38)
Click to collapseToggle
Products (38)
Click to collapse
CVEs (42)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Use After Free vulnerability in Secomea SiteManager Embedded allows Obstruction. |
Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information. |
Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked. |
1Secomea 12Sitemanager 1129 Firmware Sitemanager 1139 FirmwareSitemanager 1149 Firmware+9 moreJun 17, 2026 Apr 19, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modules) allows Exploiting Trust in Client. |
1Secomea 12Sitemanager 1129 Firmware Sitemanager 1139 FirmwareSitemanager 1149 Firmware+9 moreJun 17, 2026 Dec 13, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner. |
A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. This issue affects: Secomea GateManager versions from 9.4 through 9.7...Show more |
Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface. This issue affects: Secomea GateManager versions...Show more |
Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information. This issue affects: GateManager all versions prior to 9.7. |
1Secomea 4Gatemanager 4250 Firmware Gatemanager 4260 FirmwareGatemanager 8250 Firmware+1 moreJun 17, 2026 May 4, 2022 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack connection. This issue affects: Secomea GateManager all versions prior to 9....Show more |
1Secomea 9Sitemanager 1129 Firmware Sitemanager 1139 FirmwareSitemanager 1149 Firmware+6 moreJun 17, 2026 May 4, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Stack-based Buffer Overflow vulnerability in SiteManager allows logged-in or local user to cause arbitrary code execution. This issue affects: Secomea SiteManager all versions prior to 9.7. |
1Secomea 9Sitemanager 1129 Firmware Sitemanager 1139 FirmwareSitemanager 1149 Firmware+6 moreJun 17, 2026 May 4, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue affects: Secomea SiteManager all versions prior to 9.7. |
1Secomea 4Gatemanager 4250 Firmware Gatemanager 4260 FirmwareGatemanager 8250 Firmware+1 moreJun 17, 2026 May 4, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries without logging. This issue affects: Secomea GateManager versions prior to 9.7. |
1Secomea 4Gatemanager 4250 Firmware Gatemanager 4260 FirmwareGatemanager 8250 Firmware+1 moreJun 17, 2026 May 4, 2022 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 Improper Handling of Insufficient Privileges vulnerability in Web UI of Secomea GateManager allows logged in user to access and update privileged information. This issue affects: Secomea GateManager versions prior to 9.7...Show more |
1Secomea 4Gatemanager 4250 Firmware Gatemanager 4260 FirmwareGatemanager 8250 Firmware+1 moreJun 17, 2026 May 4, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site Scripting (XSS) vulnerability in Web UI of Secomea GateManager allows phishing attacker to inject javascript or html into logged in user session. |
1Secomea 4Gatemanager 4250 Firmware Gatemanager 4260 FirmwareGatemanager 8250 Firmware+1 moreJun 17, 2026 May 4, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Information Exposure vulnerability in web UI of Secomea GateManager allows logged in user to query devices outside own scope. |
1Secomea 4Gatemanager 4250 Firmware Gatemanager 4260 FirmwareGatemanager 8250 Firmware+1 moreJun 17, 2026 May 4, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Logging of Excessive Data vulnerability in audit log of Secomea GateManager allows logged in user to write text entries in audit log. This issue affects: Secomea GateManager versions prior to 9.7. |
1Secomea 4Gatemanager 4250 Firmware Gatemanager 4260 FirmwareGatemanager 8250 Firmware+1 moreJun 17, 2026 May 4, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user session. |
1Secomea 14Gatemanager 4250 Firmware Gatemanager 4260 FirmwareGatemanager 8250 Firmware+11 moreJun 17, 2026 May 4, 2022 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks. This issue affects: Secomea SiteManager All versions prior to 9.7. Seco...Show more |
Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject javascript in browser session. This issue affects: Secomea GateManager Version 9.6.621421014 and all pri...Show more |
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logged in LinkManager user to access stored Si...Show more |