Secomea / GateManager
37 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-1759 | Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege Escalation. This issue affects GateManager: 1… | MEDIUM | 6.5 | Sep 15, 2026 |
| CVE-2026-1758 | Session Fixation | HIGH | 8.3 | Sep 15, 2026 |
| CVE-2025-14716 | Unauthorized access to information | MEDIUM | 6.5 | Mar 19, 2026 |
| CVE-2021-32007 | Missing security header: Referrer-Policy URL | LOW | 3.5 | Dec 13, 2024 |
| CVE-2024-1969 | Heap buffer overflow | HIGH | 8.2 | Apr 29, 2024 |
| CVE-2024-1579 | Insufficient seeding of random number generator | HIGH | 8.1 | Apr 29, 2024 |
| CVE-2023-3675 | Insufficient input validation when downloading certain file types. | MEDIUM | 6.5 | Apr 18, 2024 |
| CVE-2023-0317 | GateManager debug interface is included in non-debug builds | MEDIUM | 4.9 | Apr 19, 2023 |
| CVE-2022-4308 | Clear-text passwords in configuration files | HIGH | 8.8 | Apr 19, 2023 |
| CVE-2022-2752 | Potential vulnerabilities in GM login process | HIGH | 7.8 | Dec 9, 2022 |
| CVE-2022-38123 | Insufficient validation of plugin files | HIGH | 8.7 | Dec 6, 2022 |
| CVE-2022-25786 | GateManager debug interface is included in production builds | MEDIUM | 4.9 | May 4, 2022 |
| CVE-2022-25787 | GTA URLs issued by LMM WEB API may leak information | HIGH | 7.5 | May 4, 2022 |
| CVE-2022-25783 | Hacking attempts from logged-in users are not properly logged by GM | MEDIUM | 4.3 | May 4, 2022 |
| CVE-2022-25782 | Insufficient privilege checks on object access and updates. | MEDIUM | 5.4 | May 4, 2022 |
| CVE-2022-25781 | Reflected XSS issues in GateManager | MEDIUM | 6.1 | May 4, 2022 |
| CVE-2022-25780 | Information leak via device availability query function | MEDIUM | 4.3 | May 4, 2022 |
| CVE-2022-25779 | Insufficient scope checks allows adding unrelated audit log entries | MEDIUM | 4.3 | May 4, 2022 |
| CVE-2022-25778 | Unload handlers may unintentionally defeat CSRF guards | HIGH | 8.8 | May 4, 2022 |
| CVE-2021-32010 | Clients may connect to a GateManager with TLS 1.0 | HIGH | 8.1 | May 4, 2022 |
| CVE-2021-32009 | Missing XSS guards on firmware page | MEDIUM | 6.1 | Mar 11, 2022 |
| CVE-2021-32006 | GateManager information leak for LinkManager Users | MEDIUM | 5.0 | Mar 7, 2022 |
| CVE-2021-32008 | Logged-in Administrator may get unrestricted file system access | CRITICAL | 9.9 | Mar 4, 2022 |
| CVE-2021-32004 | GateManager does not enforce strict hostname matching for WEB server | MEDIUM | 5.3 | Nov 22, 2021 |
| CVE-2020-29030 | Insufficient CSRF guards | HIGH | 8.8 | Mar 5, 2021 |
Showing 1 to 25 of 37 CVEs