Skip to content
Noroxi

Secomea records

44 published records for vendor secomea.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
2.3%
Median publish → KEV
No record has entered KEV

All records

44 records
  • OFF-BY-ONE ERROR CWE-193

    CriticalCVSS 9.8No exploitEPSS 2%

    secomea · gatemanager 8250 firmwareAug 25, 2020

  • OFF-BY-ONE ERROR CWE-193

    CriticalCVSS 9.8No exploitEPSS 2%

    secomea · gatemanager 8250 firmwareAug 25, 2020

  • IMPROPER NEUTRALIZATION OF NULL BYTE OR NUL CHARACTER CWE-158

    CriticalCVSS 9.8No exploitEPSS 2%

    secomea · gatemanager 8250 firmwareAug 25, 2020

  • Insufficient CSRF guards

    HighCVSS 8.8No exploitEPSS 1%

    secomea · gatemanager firmwareMar 5, 2021

  • Unload handlers may unintentionally defeat CSRF guards

    HighCVSS 8.8No exploitEPSS 0%

    secomea · gatemanager 4250 firmwareMay 4, 2022

  • CVE-2022-4308
    35Monitor

    Clear-text passwords in configuration files

    HighCVSS 8.8No exploitEPSS 0%

    secomea · gatemanagerApr 19, 2023

  • Logged-in Administrator may get unrestricted file system access

    HighCVSS 8.7No exploitEPSS 1%

    secomea · gatemanagerMar 4, 2022

  • Insecure Direct Object Reference in GateManager WebUI can cause privilege escalation

    HighCVSS 8.1No exploitEPSS 1%

    secomea · gatemanager 8250 firmwareFeb 15, 2021

  • CVE-2024-1579
    32Monitor

    Insufficient seeding of random number generator

    HighCVSS 8.1No exploitEPSS 1%

    secomea · gatemanagerApr 29, 2024

  • CVE-2024-1969
    32Monitor

    Heap buffer overflow

    HighCVSS 8.2No exploitEPSS 0%

    secomea · gatemanagerApr 29, 2024

  • Clients may connect to a GateManager with TLS 1.0

    HighCVSS 8.1No exploitEPSS 0%

    secomea · sitemanager 1129 firmwareMay 4, 2022

  • CVE-2022-2752
    31Monitor

    Potential vulnerabilities in GM login process

    HighCVSS 7.8No exploitEPSS 0%

    secomea · gatemanagerDec 9, 2022

  • USE OF PASSWORD HASH WITH INSUFFICIENT COMPUTATIONAL EFFORT CWE-916

    HighCVSS 7.5No exploitEPSS 1%

    secomea · gatemanager 8250 firmwareAug 25, 2020

  • CVE-2023-2912
    30Monitor

    SiteManager Embedded service disruption

    HighCVSS 7.5No exploitEPSS 1%

    secomea · sitemanager embeddedJul 17, 2023

  • Reject Remote Management via Cellular UPLINK2

    HighCVSS 7.2No exploitEPSS 2%

    secomea · sitemanager firmwareMar 5, 2021

  • Stack-based Buffer Overflow vulnerability in SiteManager allows logged-in or local user to cause arbitrary code execution.

    HighCVSS 7.2No exploitEPSS 1%

    secomea · sitemanager 1129 firmwareMay 4, 2022

  • Insufficient validation of plugin files

    HighCVSS 7.2No exploitEPSS 1%

    secomea · gatemanagerDec 6, 2022

  • Add integrity check of GateManager firmware

    HighCVSS 7.2No exploitEPSS 0%

    secomea · gatemanager 8250 firmwareMar 5, 2021

  • A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with adminis

    MediumCVSS 6.5No exploitEPSS 1%

    secomea · gatemanager 8250 firmwareFeb 15, 2021

  • Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.

    MediumCVSS 6.5No exploitEPSS 1%

    secomea · sitemanager 1129 firmwareDec 13, 2022

  • GTA URLs issued by LMM WEB API may leak information

    MediumCVSS 6.7No exploitEPSS 0%

    secomea · gatemanager 4250 firmwareMay 4, 2022

  • XSS issue due to insufficient sanitization of input field

    MediumCVSS 6.1No exploitEPSS 1%

    secomea · gatemanager firmwareMar 5, 2021

  • Reflected XSS issues

    MediumCVSS 6.1No exploitEPSS 1%

    secomea · gatemanager firmwareMar 5, 2021

  • DOM-based Javascript injection

    MediumCVSS 6.1No exploitEPSS 1%

    secomea · sitemanager embeddedFeb 16, 2021

  • Missing XSS guards on firmware page

    MediumCVSS 6.1No exploitEPSS 0%

    secomea · gatemanagerMar 11, 2022