CVE-2021-32003

HIGH

Secomea SiteManager <9.5 - Info Disclosure

Title source: llm

Description

Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.

Scores

CVSS v3 8.0
EPSS 0.0004
EPSS Percentile 12.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-523 CWE-522
Status published

Affected Products (1)

secomea/sitemanager_firmware < 9.5.621256022

Timeline

Published Aug 05, 2021
Tracked Since Feb 18, 2026