CVE-2020-29031

HIGH

Secomea Gatemanager 8250 Firmware - Improper Privilege Management

Title source: rule
STIX 2.1

Description

An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c

Scores

CVSS v3 7.1
EPSS 0.0022
EPSS Percentile 43.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Details

CWE
CWE-269 CWE-280
Status published
Products (4)
secomea/gatemanager_4250_firmware < 9.0i
secomea/gatemanager_4260_firmware < 9.0i
secomea/gatemanager_8250_firmware < 9.2c
secomea/gatemanager_9250_firmware < 9.0i
Published Feb 15, 2021
Tracked Since Feb 18, 2026