PT-2021-19622 · Secomea · Secomea Sitemanager
Published
2021-08-05
·
Updated
2022-07-02
·
CVE-2021-32002
CVSS v3.1
4.3
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Secomea SiteManager versions prior to 9.5 on Hardware.
Description:
The issue is related to an Improper Access Control vulnerability in the web service of Secomea SiteManager. This allows a local attacker without credentials to gather network information and configuration of the SiteManager.
Recommendations:
For versions prior to 9.5 on Hardware, update to version 9.5 or later to resolve the issue.
Fix
Improper Access Control
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Secomea Sitemanager