Lucene search

K
cveSecomeaCVE-2023-0317
HistoryApr 19, 2023 - 12:15 p.m.

CVE-2023-0317

2023-04-1912:15:07
CWE-420
Secomea
web.nvd.nist.gov
23
cve-2023-0317
unprotected alternate channel
gatemanager
debug console
vulnerability
sensitive information

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

5

Confidence

High

EPSS

0.001

Percentile

24.1%

Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information.

Affected configurations

Nvd
Node
secomeagatemanagerRange<10.0.622425017
VendorProductVersionCPE
secomeagatemanager*cpe:2.3:a:secomea:gatemanager:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "GateManager",
    "vendor": "Secomea",
    "versions": [
      {
        "lessThan": "10.1",
        "status": "affected",
        "version": "10.0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

5

Confidence

High

EPSS

0.001

Percentile

24.1%

Related for CVE-2023-0317