Directory Traversal Vulnerability in GateManager by Secomea
CVE-2020-29026

9CRITICAL

Key Information:

Vendor

Secomea

Vendor
CVE Published:
15 February 2021

What is CVE-2020-29026?

A directory traversal vulnerability exists in the file upload function of Secomea's GateManager, allowing an authenticated attacker with administrative access to read and write files anywhere in the Linux file system. This issue represents a significant security risk, particularly for systems running versions before 9.2c, as it can lead to unauthorized access and potential data compromise.

Affected Version(s)

GateManager All < 9.2c

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.