CVE-2021-32002

MEDIUM

Secomea SiteManager < 9.5.621256022 - Unauthenticated Information Disclosure via Web Service

Title source: llm
STIX 2.1

Description

Improper Access Control vulnerability in web service of Secomea SiteManager allows local attacker without credentials to gather network information and configuration of the SiteManager. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0023
EPSS Percentile 13.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200 CWE-284
Status published
Products (1)
secomea/sitemanager_firmware < 9.5.621256022
Published Aug 05, 2021
Tracked Since Feb 18, 2026