PT-2024-18147 · Secomea · Secomea Gatemanager

Published

2024-04-29

·

Updated

2024-04-30

·

CVE-2024-1579

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Secomea GateManager versions prior to 11.2.624071020
Description The issue is related to the incorrect usage of seeds in the Pseudo-Random Number Generator (PRNG) in the Secomea GateManager's Webserver modules, allowing session hijacking.
Recommendations For versions prior to 11.2.624071020, update to a version equal to or later than 11.2.624071020 to resolve the issue. As a temporary workaround, consider restricting access to the Webserver modules until a patch is applied.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-1579

Affected Products

Secomea Gatemanager