CVE-2020-29024

MEDIUM

Secomea GateManager <9.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in (GTA) GoToAppliance of Secomea GateManager could allow an attacker to gain access to sensitive cookies. This issue affects: Secomea GateManager all versions prior to 9.3.

Scores

CVSS v3 5.3
EPSS 0.0010
EPSS Percentile 27.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-614 CWE-311
Status published
Products (4)
secomea/gatemanager_4250_firmware
secomea/gatemanager_4260_firmware
secomea/gatemanager_8250_firmware < 9.3
secomea/gatemanager_9250_firmware
Published Feb 16, 2021
Tracked Since Feb 18, 2026