Secomea records
44 published records for vendor secomea.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 2.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-20 Improper Input Validation3
- CWE-420 Unprotected Alternate Channel2
- CWE-274 Improper Handling of Insufficient Privileges2
- CWE-193 Off-by-one Error2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
The weakness classes this vendor ships most often: where to look.
CWEAll records
44 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-14510No exploit | OFF-BY-ONE ERROR CWE-193secomea · gatemanager 8250 firmware · CWE-193 | Critical9.8 | — | 2.5% | Aug 25, 2020 |
40Plan | CVE-2020-14508No exploit | OFF-BY-ONE ERROR CWE-193secomea · gatemanager 8250 firmware · CWE-193 | Critical9.8 | — | 2.0% | Aug 25, 2020 |
39Monitor | CVE-2020-14500No exploit | IMPROPER NEUTRALIZATION OF NULL BYTE OR NUL CHARACTER CWE-158secomea · gatemanager 8250 firmware · CWE-158 | Critical9.8 | — | 1.7% | Aug 25, 2020 |
35Monitor | CVE-2020-29030No exploit | Insufficient CSRF guardssecomea · gatemanager firmware · CWE-352 | High8.8 | — | 0.5% | Mar 5, 2021 |
35Monitor | CVE-2022-25778No exploit | Unload handlers may unintentionally defeat CSRF guardssecomea · gatemanager 4250 firmware · CWE-352 | High8.8 | — | 0.3% | May 4, 2022 |
35Monitor | CVE-2022-4308No exploit | Clear-text passwords in configuration filessecomea · gatemanager · CWE-256 | High8.8 | — | 0.2% | Apr 19, 2023 |
34Monitor | CVE-2021-32008No exploit | Logged-in Administrator may get unrestricted file system accesssecomea · gatemanager · CWE-22 | High8.7 | — | 1.0% | Mar 4, 2022 |
32Monitor | CVE-2020-29031No exploit | Insecure Direct Object Reference in GateManager WebUI can cause privilege escalationsecomea · gatemanager 8250 firmware · CWE-280 | High8.1 | — | 0.7% | Feb 15, 2021 |
32Monitor | CVE-2024-1579No exploit | Insufficient seeding of random number generatorsecomea · gatemanager · CWE-335 | High8.1 | — | 0.5% | Apr 29, 2024 |
32Monitor | CVE-2024-1969No exploit | Heap buffer overflowsecomea · gatemanager · CWE-120 | High8.2 | — | 0.5% | Apr 29, 2024 |
32Monitor | CVE-2021-32010No exploit | Clients may connect to a GateManager with TLS 1.0secomea · sitemanager 1129 firmware · CWE-326 | High8.1 | — | 0.2% | May 4, 2022 |
31Monitor | CVE-2022-2752No exploit | Potential vulnerabilities in GM login processsecomea · gatemanager · CWE-287 | High7.8 | — | 0.2% | Dec 9, 2022 |
30Monitor | CVE-2020-14512No exploit | USE OF PASSWORD HASH WITH INSUFFICIENT COMPUTATIONAL EFFORT CWE-916secomea · gatemanager 8250 firmware · CWE-916 | High7.5 | — | 0.8% | Aug 25, 2020 |
30Monitor | CVE-2023-2912No exploit | SiteManager Embedded service disruptionsecomea · sitemanager embedded · CWE-416 | High7.5 | — | 0.5% | Jul 17, 2023 |
29Monitor | CVE-2020-29020No exploit | Reject Remote Management via Cellular UPLINK2secomea · sitemanager firmware · CWE-284 | High7.2 | — | 1.7% | Mar 5, 2021 |
28Monitor | CVE-2022-25785No exploit | Stack-based Buffer Overflow vulnerability in SiteManager allows logged-in or local user to cause arbitrary code execution.secomea · sitemanager 1129 firmware · CWE-121 | High7.2 | — | 1.0% | May 4, 2022 |
28Monitor | CVE-2022-38123No exploit | Insufficient validation of plugin filessecomea · gatemanager · CWE-20 | High7.2 | — | 0.8% | Dec 6, 2022 |
28Monitor | CVE-2020-29032No exploit | Add integrity check of GateManager firmwaresecomea · gatemanager 8250 firmware · CWE-494 | High7.2 | — | 0.5% | Mar 5, 2021 |
26Monitor | CVE-2020-29026No exploit | A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with adminissecomea · gatemanager 8250 firmware · CWE-22 | Medium6.5 | — | 1.5% | Feb 15, 2021 |
26Monitor | CVE-2022-38124No exploit | Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.secomea · sitemanager 1129 firmware · CWE-267 | Medium6.5 | — | 0.5% | Dec 13, 2022 |
26Monitor | CVE-2022-25787No exploit | GTA URLs issued by LMM WEB API may leak informationsecomea · gatemanager 4250 firmware · CWE-598 | Medium6.7 | — | 0.2% | May 4, 2022 |
24Monitor | CVE-2020-29029No exploit | XSS issue due to insufficient sanitization of input fieldsecomea · gatemanager firmware · CWE-20 | Medium6.1 | — | 0.8% | Mar 5, 2021 |
24Monitor | CVE-2020-29028No exploit | Reflected XSS issuessecomea · gatemanager firmware · CWE-79 | Medium6.1 | — | 0.7% | Mar 5, 2021 |
24Monitor | CVE-2020-29025No exploit | DOM-based Javascript injectionsecomea · sitemanager embedded · CWE-79 | Medium6.1 | — | 0.6% | Feb 16, 2021 |
24Monitor | CVE-2021-32009No exploit | Missing XSS guards on firmware pagesecomea · gatemanager · CWE-79 | Medium6.1 | — | 0.5% | Mar 11, 2022 |
- CVE-2020-1451040Plan
OFF-BY-ONE ERROR CWE-193
CriticalCVSS 9.8No exploitEPSS 2%secomea · gatemanager 8250 firmwareAug 25, 2020
- CVE-2020-1450840Plan
OFF-BY-ONE ERROR CWE-193
CriticalCVSS 9.8No exploitEPSS 2%secomea · gatemanager 8250 firmwareAug 25, 2020
- CVE-2020-1450039Monitor
IMPROPER NEUTRALIZATION OF NULL BYTE OR NUL CHARACTER CWE-158
CriticalCVSS 9.8No exploitEPSS 2%secomea · gatemanager 8250 firmwareAug 25, 2020
- CVE-2020-2903035Monitor
Insufficient CSRF guards
HighCVSS 8.8No exploitEPSS 1%secomea · gatemanager firmwareMar 5, 2021
- CVE-2022-2577835Monitor
Unload handlers may unintentionally defeat CSRF guards
HighCVSS 8.8No exploitEPSS 0%secomea · gatemanager 4250 firmwareMay 4, 2022
- CVE-2022-430835Monitor
Clear-text passwords in configuration files
HighCVSS 8.8No exploitEPSS 0%secomea · gatemanagerApr 19, 2023
- CVE-2021-3200834Monitor
Logged-in Administrator may get unrestricted file system access
HighCVSS 8.7No exploitEPSS 1%secomea · gatemanagerMar 4, 2022
- CVE-2020-2903132Monitor
Insecure Direct Object Reference in GateManager WebUI can cause privilege escalation
HighCVSS 8.1No exploitEPSS 1%secomea · gatemanager 8250 firmwareFeb 15, 2021
- CVE-2024-157932Monitor
Insufficient seeding of random number generator
HighCVSS 8.1No exploitEPSS 1%secomea · gatemanagerApr 29, 2024
- CVE-2024-196932Monitor
Heap buffer overflow
HighCVSS 8.2No exploitEPSS 0%secomea · gatemanagerApr 29, 2024
- CVE-2021-3201032Monitor
Clients may connect to a GateManager with TLS 1.0
HighCVSS 8.1No exploitEPSS 0%secomea · sitemanager 1129 firmwareMay 4, 2022
- CVE-2022-275231Monitor
Potential vulnerabilities in GM login process
HighCVSS 7.8No exploitEPSS 0%secomea · gatemanagerDec 9, 2022
- CVE-2020-1451230Monitor
USE OF PASSWORD HASH WITH INSUFFICIENT COMPUTATIONAL EFFORT CWE-916
HighCVSS 7.5No exploitEPSS 1%secomea · gatemanager 8250 firmwareAug 25, 2020
- CVE-2023-291230Monitor
SiteManager Embedded service disruption
HighCVSS 7.5No exploitEPSS 1%secomea · sitemanager embeddedJul 17, 2023
- CVE-2020-2902029Monitor
Reject Remote Management via Cellular UPLINK2
HighCVSS 7.2No exploitEPSS 2%secomea · sitemanager firmwareMar 5, 2021
- CVE-2022-2578528Monitor
Stack-based Buffer Overflow vulnerability in SiteManager allows logged-in or local user to cause arbitrary code execution.
HighCVSS 7.2No exploitEPSS 1%secomea · sitemanager 1129 firmwareMay 4, 2022
- CVE-2022-3812328Monitor
Insufficient validation of plugin files
HighCVSS 7.2No exploitEPSS 1%secomea · gatemanagerDec 6, 2022
- CVE-2020-2903228Monitor
Add integrity check of GateManager firmware
HighCVSS 7.2No exploitEPSS 0%secomea · gatemanager 8250 firmwareMar 5, 2021
- CVE-2020-2902626Monitor
A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with adminis
MediumCVSS 6.5No exploitEPSS 1%secomea · gatemanager 8250 firmwareFeb 15, 2021
- CVE-2022-3812426Monitor
Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.
MediumCVSS 6.5No exploitEPSS 1%secomea · sitemanager 1129 firmwareDec 13, 2022
- CVE-2022-2578726Monitor
GTA URLs issued by LMM WEB API may leak information
MediumCVSS 6.7No exploitEPSS 0%secomea · gatemanager 4250 firmwareMay 4, 2022
- CVE-2020-2902924Monitor
XSS issue due to insufficient sanitization of input field
MediumCVSS 6.1No exploitEPSS 1%secomea · gatemanager firmwareMar 5, 2021
- CVE-2020-2902824Monitor
Reflected XSS issues
MediumCVSS 6.1No exploitEPSS 1%secomea · gatemanager firmwareMar 5, 2021
- CVE-2020-2902524Monitor
DOM-based Javascript injection
MediumCVSS 6.1No exploitEPSS 1%secomea · sitemanager embeddedFeb 16, 2021
- CVE-2021-3200924Monitor
Missing XSS guards on firmware page
MediumCVSS 6.1No exploitEPSS 0%secomea · gatemanagerMar 11, 2022