Lucene search

K
cveSecomeaCVE-2022-25787
HistoryMay 04, 2022 - 2:15 p.m.

CVE-2022-25787

2022-05-0414:15:08
CWE-200
CWE-598
Secomea
web.nvd.nist.gov
715
cve
2022
25787
information exposure
query strings
get request
vulnerability
lmm api
secomea gatemanager
hijack connection
nvd

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.5

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

6.4

Confidence

High

EPSS

0

Percentile

12.6%

Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack connection. This issue affects: Secomea GateManager all versions prior to 9.7.

Affected configurations

Nvd
Node
secomeagatemanager_4250_firmwareRange<9.7.622134021
AND
secomeagatemanager_4250Match-
Node
secomeagatemanager_4260_firmwareRange<9.7.622134021
AND
secomeagatemanager_4260Match-
Node
secomeagatemanager_8250_firmwareRange<9.7.622134021
AND
secomeagatemanager_8250Match-
Node
secomeagatemanager_9250_firmwareRange<9.7.622134021
AND
secomeagatemanager_9250Match-
VendorProductVersionCPE
secomeagatemanager_4250_firmware*cpe:2.3:o:secomea:gatemanager_4250_firmware:*:*:*:*:*:*:*:*
secomeagatemanager_4250-cpe:2.3:h:secomea:gatemanager_4250:-:*:*:*:*:*:*:*
secomeagatemanager_4260_firmware*cpe:2.3:o:secomea:gatemanager_4260_firmware:*:*:*:*:*:*:*:*
secomeagatemanager_4260-cpe:2.3:h:secomea:gatemanager_4260:-:*:*:*:*:*:*:*
secomeagatemanager_8250_firmware*cpe:2.3:o:secomea:gatemanager_8250_firmware:*:*:*:*:*:*:*:*
secomeagatemanager_8250-cpe:2.3:h:secomea:gatemanager_8250:-:*:*:*:*:*:*:*
secomeagatemanager_9250_firmware*cpe:2.3:o:secomea:gatemanager_9250_firmware:*:*:*:*:*:*:*:*
secomeagatemanager_9250-cpe:2.3:h:secomea:gatemanager_9250:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "GateManager",
    "vendor": "Secomea",
    "versions": [
      {
        "lessThan": "9.7",
        "status": "affected",
        "version": "all",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.5

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

6.4

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2022-25787