CVE-2022-25779
04.05.2022, 14:15
Logging of Excessive Data vulnerability in audit log of Secomea GateManager allows logged in user to write text entries in audit log. This issue affects: Secomea GateManager versions prior to 9.7.Enginsight
Vendor | Product | Version |
---|---|---|
secomea | gatemanager_4250_firmware | 𝑥 < 9.7.622134021 |
secomea | gatemanager_4260_firmware | 𝑥 < 9.7.622134021 |
secomea | gatemanager_8250_firmware | 𝑥 < 9.7.622134021 |
secomea | gatemanager_9250_firmware | 𝑥 < 9.7.622134021 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-779 - Logging of Excessive DataThe software logs too much information, making log files hard to process and possibly hindering recovery efforts or forensic analysis after an attack.
- CWE-400 - Uncontrolled Resource ConsumptionThe software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.