CVE-2020-29026: Path Traversal
Published Feb 15, 2021
·Updated
A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with administrative permissions to read and write arbitrary files in the Linux file system. This issue affects: GateManager all versions prior to 9.2c.
Affected Software
8 affected components
Secomea Gatemanager 8250 Firmware<9.2c
Secomea Gatemanager 8250
Secomea Gatemanager 4250 Firmware<9.0i
Secomea Gatemanager 4250
Secomea Gatemanager 4260 Firmware<9.0i
Secomea Gatemanager 4260
Secomea Gatemanager 9250 Firmware<9.0i
Secomea Gatemanager 9250
Event History
Feb 15, 2021
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-29026.
2
What is the severity level of CVE-2020-29026?
CVE-2020-29026 has a severity level of critical.
3
Which software versions are affected by CVE-2020-29026?
CVE-2020-29026 affects all versions of GateManager prior to 9.2c.
4
How does CVE-2020-29026 impact the system?
CVE-2020-29026 allows an authenticated attacker with administrative permissions to read and write arbitrary files in the Linux file system.
5
Is there a fix available for CVE-2020-29026?
To mitigate CVE-2020-29026, it is recommended to update GateManager to version 9.2c or later.