CVE-2020-29032

HIGH

Secomea GateManager < 9.4.621054022 - Authenticated Code Execution via Firmware Archive Upload

Title source: llm
STIX 2.1

Description

Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious code on server. This issue affects: Secomea GateManager all versions prior to 9.4.621054022

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://www.tenable.com/security/research/tra-2021-06

Scores

CVSS v3 8.4
EPSS 0.0048
EPSS Percentile 37.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-494 CWE-434
Status published
Products (1)
secomea/gatemanager_8250_firmware < 9.4.621054022
Published Mar 05, 2021
Tracked Since Feb 18, 2026