CVE-2020-29026

CRITICAL

GateManager < 9.2c - Authenticated Path Traversal and Arbitrary File Write via File Upload Function

Title source: llm
STIX 2.1

Description

A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with administrative permissions to read and write arbitrary files in the Linux file system. This issue affects: GateManager all versions prior to 9.2c.

References (1)

Core 1
Core References

Scores

CVSS v3 9.0
EPSS 0.0146
EPSS Percentile 70.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L

Details

CWE
CWE-22
Status published
Products (4)
secomea/gatemanager_4250_firmware < 9.0i
secomea/gatemanager_4260_firmware < 9.0i
secomea/gatemanager_8250_firmware < 9.2c
secomea/gatemanager_9250_firmware < 9.0i
Published Feb 15, 2021
Tracked Since Feb 18, 2026