Missing XSS guards on firmware page
CVE-2021-32009

5MEDIUM

Key Information:

Vendor

Secomea

Vendor
CVE Published:
11 March 2022

What is CVE-2021-32009?

Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject javascript in browser session. This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions.

Affected Version(s)

GateManager All <= 9.6.621421014

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.