CVE-2020-29024

MEDIUM

Secomea GateManager <9.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in (GTA) GoToAppliance of Secomea GateManager could allow an attacker to gain access to sensitive cookies. This issue affects: Secomea GateManager all versions prior to 9.3.

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0051
EPSS Percentile 40.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-311 CWE-614
Status published
Products (4)
secomea/gatemanager_4250_firmware
secomea/gatemanager_4260_firmware
secomea/gatemanager_8250_firmware < 9.3
secomea/gatemanager_9250_firmware
Published Feb 16, 2021
Tracked Since Feb 18, 2026