CVE-2021-32002: SiteManager troubleshooter allows access without authentication from local network
Improper Access Control vulnerability in web service of Secomea SiteManager allows local attacker without credentials to gather network information and configuration of the SiteManager. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32002?
CVE-2021-32002 is an Improper Access Control vulnerability in the web service of Secomea SiteManager.
How does CVE-2021-32002 affect Secomea SiteManager?
CVE-2021-32002 allows a local attacker without credentials to gather network information and configuration of the SiteManager.
Which versions of Secomea SiteManager are affected by CVE-2021-32002?
All versions of Secomea SiteManager prior to 9.5.621256022 on Hardware are affected by CVE-2021-32002.
What is the severity of CVE-2021-32002?
CVE-2021-32002 has a severity rating of medium (3.3).
How can I fix CVE-2021-32002?
To fix CVE-2021-32002, it is recommended to update Secomea SiteManager to version 9.5.621256022 or later.