ZeroHour

CVE-2020-29031

CVSS 3.1
8.1 high
EPSS
<1%p53
Published
()
Modified
Description

An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c

Vendors
secomea
Products
gatemanager 8250 firmware, gatemanager 4250 firmware, gatemanager 4260 firmware, gatemanager 9250 firmware
Weakness
CWE-280, CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.