Vulnerabilities
61 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-55515 | A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_ipslib.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2024-7732 | Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-7731 | Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-7470 | A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been rated as critical. This issue affects the function sslvpn_config_mod of the file /vpn/vpn_template_style.php of the component Web Interface. The manipulation of the argument template/stylenum leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273563. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.3 | 25% | PoC |
| — | |
| CVE-2024-7120 | A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. This affects an unknown part of the file list_base_config.php of the component Web Interface. The manipulation of the argument template leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272451. NVD description · AI analysis pending | 5.3 | 93% | PoC |
| — | |
| CVE-2023-2912 | Use After Free vulnerability in Secomea SiteManager Embedded allows Obstruction. Use After Free vulnerability in Secomea SiteManager Embedded allows Obstruction. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2022-4308 +1 in the same advisory: …0317 | Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked. Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2022-38125 | Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modules) allows Exploiting Trust in Client. Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modules) allows Exploiting Trust in Client. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2022-38124 | Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner. Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2022-2752 | A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. This issue affects: Secomea GateManager versions from 9.4 through 9.7. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2022-38123 | Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager in Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface. This issue affects: Secomea GateManager versions prior to 10.0. NVD description · AI analysis pending | 7.2 | <1% |
| — | ||
| CVE-2022-25786 | Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information. Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information. This issue affects: GateManager all versions prior to 9.7. NVD description · AI analysis pending | 4.9 | <1% |
| — | ||
| CVE-2022-25778 | Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user session. Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user session. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2021-32010 | Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks. Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks. This issue affects: Secomea SiteManager All versions prior to 9.7. Secomea LinkManager versions prior to 9.7. Secomea GateManager versions prior to 9.7. NVD description · AI analysis pending | 8.1 group max | <1% |
| — | ||
| CVE-2022-26671 | Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system information and modify system setting to cause partial disrupt of service. NVD description · AI analysis pending | 7.3 | <1% |
| — | ||
| CVE-2021-32009 | Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject javascript in browser session. Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject javascript in browser session. This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2021-32006 | This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logged in LinkManager user to access stored SiteManager backup files. NVD description · AI analysis pending | 4.3 | <1% |
| — | ||
| CVE-2021-32005 | Cross-site Scripting (XSS) vulnerability in log view of Secomea SiteManager allows a logged in user to store javascript for later execution. Cross-site Scripting (XSS) vulnerability in log view of Secomea SiteManager allows a logged in user to store javascript for later execution. This issue affects: Secomea SiteManager Version 9.6.621421014 and all prior versions. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2021-32008 | This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories. NVD description · AI analysis pending | 8.7 | <1% |
| — | ||
| CVE-2021-32004 | This issue affects: Secomea GateManager All versions prior to 9.6. This issue affects: Secomea GateManager All versions prior to 9.6. Improper Check of host header in web server of Secomea GateManager allows attacker to cause browser cache poisoning. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2021-32003 +1 in the same advisory: …32002 | Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware. NVD description · AI analysis pending | 5.5 group max | <1% |
| — | ||
| CVE-2021-35962 | Specific page parameters in Dr. Specific page parameters in Dr. ID Door Access Control and Personnel Attendance Management system does not filter special characters. Remote attackers can apply Path Traversal means to download credential files from the system without permission. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2021-35961 | Dr. ID Door Access Control and Personnel Attendance Management system uses the hard-code admin default credentials that allows remote attackers to access the sy Dr. ID Door Access Control and Personnel Attendance Management system uses the hard-code admin default credentials that allows remote attackers to access the system through the default password and obtain the highest permission. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2020-29030 | Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute malicious code. Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute malicious code. This issue affects: Secomea GateManager All versions prior to 9.4. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2020-29020 | Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured c Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured credentials. This issue affects: Secomea SiteManager All versions prior to 9.4.620527004 on Hardware. NVD description · AI analysis pending | 7.2 | 2% |
| — | ||
| CVE-2020-29032 | Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious code on serve Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious code on server. This issue affects: Secomea GateManager all versions prior to 9.4.621054022 NVD description · AI analysis pending | 7.2 | <1% |
| — | ||
| CVE-2020-29027 | Cross-site Scripting (XSS) vulnerability in GUI of Secomea SiteManager could allow an attacker to cause an XSS Attack. Cross-site Scripting (XSS) vulnerability in GUI of Secomea SiteManager could allow an attacker to cause an XSS Attack. This issue affects: Secomea SiteManager all versions prior to 9.3. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2020-29025 | A vulnerability in SiteManager-Embedded (SM-E) Web server which may allow attacker to construct a URL that if visited by another application user, will cause Ja A vulnerability in SiteManager-Embedded (SM-E) Web server which may allow attacker to construct a URL that if visited by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application. This issue affects all versions and variants of SM-E prior to version 9.3 NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2020-29022 | Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior to 9.3 NVD description · AI analysis pending | 5.3 group max | <1% |
| — | ||
| CVE-2020-29031 | An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any us An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c NVD description · AI analysis pending | 8.1 | <1% |
| — |