PT-2021-11638 · Unknown · Gatemanager
Published
2021-02-15
·
Updated
2021-02-26
·
CVE-2020-29031
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
GateManager versions prior to 9.2c
Description:
An Insecure Direct Object Reference issue exists in the web UI of the GateManager, allowing an authenticated attacker to reset the password of any user in its domain or any sub-domain via escalation of privileges.
Recommendations:
For GateManager versions prior to 9.2c, update to version 9.2c or later to resolve the issue. As a temporary workaround, consider restricting access to the web UI or implementing additional authentication measures to minimize the risk of exploitation.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gatemanager