CRITICAL · 9.0

CVE-2020-29026

A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with administrative permissions to read and write arbitrary files in the...

Vulnerability Description

A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with administrative permissions to read and write arbitrary files in the Linux file system. This issue affects: GateManager all versions prior to 9.2c.

CVSS Score

9.0

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
LOW

Affected Products

VendorProductVersions
SecomeaGatemanager 8250 Firmware< 9.2c
SecomeaGatemanager 8250-
SecomeaGatemanager 4250 Firmware< 9.0i
SecomeaGatemanager 4250-
SecomeaGatemanager 4260 Firmware< 9.0i
SecomeaGatemanager 4260-
SecomeaGatemanager 9250 Firmware< 9.0i
SecomeaGatemanager 9250-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-29026?

CVE-2020-29026 is a vulnerability with a CVSS score of 9.0 (CRITICAL). A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with administrative permissions to read and write arbitrary files in the...

How severe is CVE-2020-29026?

CVE-2020-29026 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2020-29026?

Check the references section above for vendor advisories and patch information. Affected products include: Secomea Gatemanager 8250 Firmware, Secomea Gatemanager 8250, Secomea Gatemanager 4250 Firmware, Secomea Gatemanager 4250, Secomea Gatemanager 4260 Firmware.