CVE-2020-14500: IMPROPER NEUTRALIZATION OF NULL BYTE OR NUL CHARACTER CWE-158
Published Aug 25, 2020
·Updated
Secomea GateManager all versions prior to 9.2c, An attacker can send a negative value and overwrite arbitrary data.
Affected Software
3 affected components
Secomea Gatemanager 8250 Firmware=9.2c
Secomea Gatemanager 8250
Secomea All versions prior to 9.2c
Event History
Aug 25, 2020
CVE Published
via MITRE·01:12 PM
Data Sourced
via MITRE·01:12 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-14500?
CVE-2020-14500 is a vulnerability found in Secomea GateManager all versions prior to 9.2c where an attacker can send a negative value and overwrite arbitrary data.
2
What software is affected by CVE-2020-14500?
Secomea GateManager versions prior to 9.2c are affected by CVE-2020-14500.
3
What is the severity of CVE-2020-14500?
CVE-2020-14500 has a severity rating of 9.8, which is categorized as critical.
4
How can the CVE-2020-14500 vulnerability be fixed?
To fix the CVE-2020-14500 vulnerability, users should update their Secomea GateManager software to version 9.2c or later.
5
Are there any references for CVE-2020-14500?
Yes, you can find more information about CVE-2020-14500 at the following reference: https://us-cert.cisa.gov/ics/advisories/icsa-20-210-01