CVE-2020-29031

HIGH

GateManager < 9.2c - Authenticated Privilege Escalation via Password Reset

Title source: llm
STIX 2.1

Description

An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c

References (1)

Core 1
Core References

Scores

CVSS v3 7.1
EPSS 0.0075
EPSS Percentile 49.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Details

CWE
CWE-269 CWE-280
Status published
Products (4)
secomea/gatemanager_4250_firmware < 9.0i
secomea/gatemanager_4260_firmware < 9.0i
secomea/gatemanager_8250_firmware < 9.2c
secomea/gatemanager_9250_firmware < 9.0i
Published Feb 15, 2021
Tracked Since Feb 18, 2026