PT-2022-24217 · Secomea · Secomea Gatemanager

Published

2022-12-06

·

Updated

2022-12-08

·

CVE-2022-38123

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Secomea GateManager versions prior to 10.0
Description The issue is related to improper input validation of plugin files in the Administrator Interface of Secomea GateManager, allowing a server administrator to inject code into the GateManager interface.
Recommendations For versions prior to 10.0, update to version 10.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Administrator Interface to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-38123

Affected Products

Secomea Gatemanager