ZeroHour

Vulnerabilities

42 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-2912
Use After Free vulnerability in Secomea SiteManager Embedded allows Obstruction.

Use After Free vulnerability in Secomea SiteManager Embedded allows Obstruction.

NVD description · AI analysis pending
7.5<1%
  • secomea sitemanager embedded
CVE-2022-4308
+1 in the same advisory: …0317
Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked.

Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked.

NVD description · AI analysis pending
8.8
group max
<1%
  • secomea gatemanager
CVE-2022-38125
Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modules) allows Exploiting Trust in Client.

Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modules) allows Exploiting Trust in Client.

NVD description · AI analysis pending
5.5<1%
  • secomea sitemanager 3549 firmware
  • secomea sitemanager 3539 firmware
  • secomea sitemanager 3529 firmware
  • +1 more
CVE-2022-38124
Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.

Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.

NVD description · AI analysis pending
6.5<1%
  • secomea sitemanager 1129 firmware
  • secomea sitemanager 3329 firmware
  • secomea sitemanager 1529 firmware
  • +1 more
CVE-2022-2752
A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions.

A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. This issue affects: Secomea GateManager versions from 9.4 through 9.7.

NVD description · AI analysis pending
7.8<1%
  • secomea gatemanager
CVE-2022-38123
Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager in

Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface. This issue affects: Secomea GateManager versions prior to 10.0.

NVD description · AI analysis pending
7.2<1%
  • secomea gatemanager
CVE-2022-25786
Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information.

Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information. This issue affects: GateManager all versions prior to 9.7.

NVD description · AI analysis pending
4.9<1%
  • secomea gatemanager
CVE-2022-25778
Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user session.

Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user session.

NVD description · AI analysis pending
8.8
group max
<1%
  • secomea gatemanager 4250 firmware
  • secomea gatemanager 4260 firmware
  • secomea gatemanager 8250 firmware
  • +1 more
CVE-2021-32010
+2 in the same advisory: …25785 …25784
Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks.

Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks. This issue affects: Secomea SiteManager All versions prior to 9.7. Secomea LinkManager versions prior to 9.7. Secomea GateManager versions prior to 9.7.

NVD description · AI analysis pending
8.1
group max
<1%
  • secomea sitemanager 1129 firmware
  • secomea sitemanager 1139 firmware
  • secomea sitemanager 1149 firmware
  • +1 more
CVE-2021-32009
Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject javascript in browser session.

Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject javascript in browser session. This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions.

NVD description · AI analysis pending
6.1<1%
  • secomea gatemanager
CVE-2021-32006
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions.

This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logged in LinkManager user to access stored SiteManager backup files.

NVD description · AI analysis pending
4.3<1%
  • secomea gatemanager
CVE-2021-32005
Cross-site Scripting (XSS) vulnerability in log view of Secomea SiteManager allows a logged in user to store javascript for later execution.

Cross-site Scripting (XSS) vulnerability in log view of Secomea SiteManager allows a logged in user to store javascript for later execution. This issue affects: Secomea SiteManager Version 9.6.621421014 and all prior versions.

NVD description · AI analysis pending
5.4<1%
  • secomea sitemanager 1129 firmware
  • secomea sitemanager 1139 firmware
  • secomea sitemanager 1149 firmware
  • +1 more
CVE-2021-32008
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions.

This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.

NVD description · AI analysis pending
8.7<1%
  • secomea gatemanager
CVE-2021-32004
This issue affects: Secomea GateManager All versions prior to 9.6.

This issue affects: Secomea GateManager All versions prior to 9.6. Improper Check of host header in web server of Secomea GateManager allows attacker to cause browser cache poisoning.

NVD description · AI analysis pending
5.3<1%
  • secomea gatemanager 8250 firmware
CVE-2021-32003
+1 in the same advisory: …32002
Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after

Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.

NVD description · AI analysis pending
5.5
group max
<1%
  • secomea sitemanager firmware
CVE-2020-29030
+2 in the same advisory: …29029 …29028
Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute malicious code.

Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute malicious code. This issue affects: Secomea GateManager All versions prior to 9.4.

NVD description · AI analysis pending
8.8
group max
<1%
  • secomea gatemanager firmware
CVE-2020-29020
Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured c

Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured credentials. This issue affects: Secomea SiteManager All versions prior to 9.4.620527004 on Hardware.

NVD description · AI analysis pending
7.22%
  • secomea sitemanager firmware
CVE-2020-29032
Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious code on serve

Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious code on server. This issue affects: Secomea GateManager all versions prior to 9.4.621054022

NVD description · AI analysis pending
7.2<1%
  • secomea gatemanager 8250 firmware
CVE-2020-29027
Cross-site Scripting (XSS) vulnerability in GUI of Secomea SiteManager could allow an attacker to cause an XSS Attack.

Cross-site Scripting (XSS) vulnerability in GUI of Secomea SiteManager could allow an attacker to cause an XSS Attack. This issue affects: Secomea SiteManager all versions prior to 9.3.

NVD description · AI analysis pending
5.4<1%
  • secomea sitemanager 1129 firmware
  • secomea sitemanager 1139 firmware
  • secomea sitemanager 1149 firmware
  • +1 more
CVE-2020-29025
A vulnerability in SiteManager-Embedded (SM-E) Web server which may allow attacker to construct a URL that if visited by another application user, will cause Ja

A vulnerability in SiteManager-Embedded (SM-E) Web server which may allow attacker to construct a URL that if visited by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application. This issue affects all versions and variants of SM-E prior to version 9.3

NVD description · AI analysis pending
6.1<1%
  • secomea sitemanager embedded
CVE-2020-29022
+2 in the same advisory: …29024 …29023
Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks.

Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior to 9.3

NVD description · AI analysis pending
5.3
group max
<1%
  • secomea gatemanager 4250 firmware
  • secomea gatemanager 4260 firmware
  • secomea gatemanager 9250 firmware
  • +1 more
CVE-2020-29031
+1 in the same advisory: …29026
An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any us

An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c

NVD description · AI analysis pending
8.1
group max
<1%
  • secomea gatemanager 8250 firmware
  • secomea gatemanager 4250 firmware
  • secomea gatemanager 4260 firmware
  • +1 more
CVE-2020-29021
A vulnerability in web UI input field of GateManager allows authenticated attacker to enter script tags that could cause XSS.

A vulnerability in web UI input field of GateManager allows authenticated attacker to enter script tags that could cause XSS. This issue affects: GateManager all versions prior to 9.3.

NVD description · AI analysis pending
4.8<1%
  • secomea gatemanager 8250 firmware
  • secomea gatemanager 4250 firmware
  • secomea gatemanager 4260 firmware
  • +1 more
CVE-2020-14510
+3 in the same advisory: …14508 …14500 …14512
GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for telnet, allowing an unprivileged attacker to execute commands as r

GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for telnet, allowing an unprivileged attacker to execute commands as root.

NVD description · AI analysis pending
9.8
group max
2%
  • secomea gatemanager 8250 firmware