Gatemanager
Vendor:
First CVE: Feb 8, 2021 · Active for 5 years
30
Total CVEs
More Total CVEs than 97% of tracked products
7.5
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Gatemanager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 8, 2021
5 years ago
Most Recent CVE
Dec 13, 2024
592 days ago
CVE Severity & Scoring
Gatemanager30 CVEs
60%
33%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local3 (10.0%)
Network27 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (96.7%)
High1 (3.3%)
Unknown0 (0.0%)
User Interaction
None21 (70.0%)
Unknown0 (0.0%)
Required9 (30.0%)
Privileges Required
Low10 (33.3%)
High9 (30.0%)
None11 (36.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32008HIGH This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin | Mar 4, 2022 | 8.7 | 28 | NO | NO |
CVE-2022-4308HIGH Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked. | Apr 19, 2023 | 8.8 | 27 | NO | NO |
CVE-2020-29030HIGH Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute malicious code. This issue affects: Secomea GateManager All versions | Mar 5, 2021 | 8.8 | 27 | NO | NO |
CVE-2022-2752HIGH A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions.
This issue affects:
Secomea G | Dec 9, 2022 | 7.8 | 25 | NO | NO |
CVE-2020-29031HIGH An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or | Feb 15, 2021 | 8.1 | 25 | NO | NO |
CVE-2024-1969HIGH Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Secomea GateManager (webserver modules) allows crash of GateManager.This issue affects GateM | Apr 29, 2024 | 8.2 | 24 | NO | NO |
CVE-2022-38123HIGH Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface.
This issue | Dec 6, 2022 | 7.2 | 24 | NO | NO |
CVE-2024-1579HIGH Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Secomea GateManager (Webserver modules) allows Session Hijacking.This issue affects GateManager: | Apr 29, 2024 | 8.1 | 23 | NO | NO |
CVE-2020-29032HIGH Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious code on server. This issue affect | Mar 5, 2021 | 7.2 | 22 | NO | NO |
CVE-2022-25787MEDIUM Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack connection. This issue affects: Seco | May 4, 2022 | 6.7 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (30 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (30 CVEs).
Media Mentions
Signals from CVEs in this product scope (30 CVEs).
Top CWEs
Versions
No cataloged versions.