CVEs we hold for Secomea
Records whose assigning authority named Secomea as the affected vendor. Newest identifiers first, capped at 200.
CVE-2024-1579Insufficient seeding of random number generatorSecomea GateManager CVE-2023-3675Insufficient input validation when downloading certain file types.Secomea GateManager CVE-2023-2912SiteManager Embedded service disruptionSecomea SiteManager Embedded CVE-2023-0317GateManager debug interface is included in non-debug buildsSecomea GateManager CVE-2022-4308Clear-text passwords in configuration filesSecomea GateManager CVE-2022-38125FTP Agent forwards traffic on inactive ports to LinkManagerSecomea SiteManager CVE-2022-38123Insufficient validation of plugin filesSecomea GateManager CVE-2022-2752Potential vulnerabilities in GM login processSecomea GateManager CVE-2022-25787GTA URLs issued by LMM WEB API may leak informationSecomea GateManager CVE-2022-25786GateManager debug interface is included in production buildsSecomea GateManager CVE-2022-25784User controllable HTML element attribute (potential XSS)Secomea SiteManager CVE-2022-25783Hacking attempts from logged-in users are not properly logged by GMSecomea GateManager CVE-2022-25782Insufficient privilege checks on object access and updates.Secomea GateManager CVE-2022-25780Information leak via device availability query functionSecomea GateManager CVE-2022-25779Insufficient scope checks allows adding unrelated audit log entriesSecomea GateManager CVE-2022-25778Unload handlers may unintentionally defeat CSRF guardsSecomea GateManager CVE-2021-32010Clients may connect to a GateManager with TLS 1.0Secomea GateManager CVE-2021-32008Logged-in Administrator may get unrestricted file system accessSecomea GateManager CVE-2021-32007Missing security header: Referrer-Policy URLSecomea GateManager CVE-2021-32006GateManager information leak for LinkManager UsersSecomea GateManager CVE-2021-32004GateManager does not enforce strict hostname matching for WEB serverSecomea GateManager CVE-2021-32003Configuration service port remains open 10 minutes after reboot even when already provisionedSecomea SiteManager CVE-2021-32002SiteManager troubleshooter allows access without authentication from local networkSecomea SiteManager CVE-2020-29032Add integrity check of GateManager firmwareSecomea GateManager CVE-2020-29031Insecure Direct Object Reference in GateManager WebUI can cause privilege escalationSecomea GateManager CVE-2020-29029XSS issue due to insufficient sanitization of input fieldSecomea GateManager CVE-2020-29025DOM-based Javascript injectionSecomea SiteManager Embedded (SM-E) CVE-2020-29023CSV Formula Injection possible due to improper fields escaping in GateManagerSecomea GateManager CVE-2020-29022Host Header Injection allowing web cache poisoning attacksSecomea GateManager CVE-2020-29021Scripting tag chars < > not filtered in input fields could cause Cross-Site Scripting (XSS)Secomea GateManager CVE-2020-29020Reject Remote Management via Cellular UPLINK2Secomea SiteManager CVE-2020-14512USE OF PASSWORD HASH WITH INSUFFICIENT COMPUTATIONAL EFFORT CWE-916Secomea GateManager CVE-2020-14500IMPROPER NEUTRALIZATION OF NULL BYTE OR NUL CHARACTER CWE-158Secomea GateManager all versions prior to 9.2c 49 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.