CVE-2022-25787

EUVD-2022-30427
Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack connection. This issue affects: Secomea GateManager all versions prior to 9.7.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
LOCAL
HIGH
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
SecomeaCNA
7.5 HIGH
LOCAL
HIGH
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
Affected Products (NVD)
VendorProductVersion
secomeagatemanager_4250_firmware
𝑥
< 9.7.622134021
secomeagatemanager_4260_firmware
𝑥
< 9.7.622134021
secomeagatemanager_8250_firmware
𝑥
< 9.7.622134021
secomeagatemanager_9250_firmware
𝑥
< 9.7.622134021
𝑥
= Vulnerable software versions