CVE-2020-14510: OFF-BY-ONE ERROR CWE-193
Published Aug 25, 2020
·Updated
GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for telnet, allowing an unprivileged attacker to execute commands as root.
Affected Software
3 affected components
Secomea Gatemanager 8250 Firmware=9.2c
Secomea Gatemanager 8250
Secomea All versions prior to 9.2c
Event History
Aug 25, 2020
CVE Published
via MITRE·01:19 PM
Data Sourced
via MITRE·01:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-14510.
2
What is the severity level of CVE-2020-14510?
CVE-2020-14510 has a severity level of critical (9.8).
3
Which GateManager versions are affected by CVE-2020-14510?
GateManager versions prior to 9.2c are affected by CVE-2020-14510.
4
What is the impact of CVE-2020-14510?
CVE-2020-14510 allows an unprivileged attacker to execute commands as root.
5
Is there a fix available for CVE-2020-14510?
It is recommended to update to version 9.2c or later to mitigate CVE-2020-14510.