CVE-2021-32004: GateManager does not enforce strict hostname matching for WEB server
Published Nov 22, 2021
·Updated
This issue affects: Secomea GateManager All versions prior to 9.6. Improper Check of host header in web server of Secomea GateManager allows attacker to cause browser cache poisoning.
Affected Software
2 affected components
Secomea Gatemanager 8250 Firmware<9.6
Secomea Gatemanager 8250
Event History
Nov 22, 2021
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-32004?
CVE-2021-32004 is a vulnerability that affects Secomea GateManager versions prior to 9.6, and allows an attacker to cause browser cache poisoning.
2
How does CVE-2021-32004 impact Secomea GateManager?
CVE-2021-32004 allows an attacker to exploit the improper check of the host header in the web server of Secomea GateManager, leading to browser cache poisoning.
3
What is the severity of CVE-2021-32004?
The severity of CVE-2021-32004 is medium, with a severity score of 5.3.
4
What versions of Secomea GateManager are affected by CVE-2021-32004?
Secomea GateManager versions prior to 9.6 are affected by CVE-2021-32004.
5
How can I fix CVE-2021-32004?
To fix CVE-2021-32004, it is recommended to update Secomea GateManager to version 9.6 or later.