Secomea A/S develops a focused product line of industrial remote-access and secure connectivity appliances, particularly its GateManager series, which serve as gateways for secure access to operational technology and enterprise networks. The vendor's vulnerability profile clusters around web-facing input handling and access control, with recurring weakness classes including cross-site scripting, improper input validation, exposure of sensitive information, and improper privilege management that reflect the authentication and web-interface demands of gateway appliances. A meaningful share of vulnerabilities reach serious severity, underscoring the criticality of these devices to industrial and enterprise network security. Defenders should track this vendor's advisories closely for gateway deployments and prioritize patching of internet-reachable or externally accessible instances. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Secomea A/S over time
Signals from CVEs in this vendor scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-14500CRITICAL Secomea GateManager all versions prior to 9.2c, An attacker can send a negative value and overwrite arbitrary data. | Aug 25, 2020 | 9.8 | 30 | NO | NO |
CVE-2021-32008HIGH This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin | Mar 4, 2022 | 8.7 | 28 | NO | NO |
CVE-2022-4308HIGH Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked. | Apr 19, 2023 | 8.8 | 27 | NO | NO |
CVE-2020-29030HIGH Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute malicious code. This issue affects: Secomea GateManager All versions | Mar 5, 2021 | 8.8 | 27 | NO | NO |
CVE-2022-2752HIGH A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions.
This issue affects:
Secomea G | Dec 9, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-32010HIGH Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks. This issue affects: Secomea Sit | May 4, 2022 | 8.1 | 25 | NO | NO |
CVE-2020-29031HIGH An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or | Feb 15, 2021 | 8.1 | 25 | NO | NO |
CVE-2020-14512HIGH GateManager versions prior to 9.2c, The affected product uses a weak hash type, which may allow an attacker to view user passwords. | Aug 25, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-14510CRITICAL GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for telnet, allowing an unprivileged attacker to execute commands as root. | Aug 25, 2020 | 9.8 | 25 | NO | NO |
CVE-2024-1969HIGH Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Secomea GateManager (webserver modules) allows crash of GateManager.This issue affects GateM | Apr 29, 2024 | 8.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (46 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Secomea A/S.
Media articles that mention a CVE ID that affects a product developed by Secomea A/S — matched by CVE ID, not by vendor name.