CVE-2021-32008: Logged-in Administrator may get unrestricted file system access
Published Mar 4, 2022
·Updated
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.
Affected Software
1 affected component
Secomea GateManager<=9.6.621421014
Event History
Mar 4, 2022
CVE Published
via MITRE·09:20 PM
Data Sourced
via MITRE·09:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-32008?
The severity of CVE-2021-32008 is critical with a CVSS score of 8.7.
2
Which version of Secomea GateManager is affected by CVE-2021-32008?
Secomea GateManager Version 9.6.621421014 and all prior versions are affected by CVE-2021-32008.
3
What is the nature of the vulnerability in CVE-2021-32008?
CVE-2021-32008 is an improper limitation of a pathname to a restricted directory vulnerability.
4
What can an authenticated GateManager admin do with CVE-2021-32008?
An authenticated GateManager admin can use CVE-2021-32008 to delete system files or directories.
5
How can I fix CVE-2021-32008 in Secomea GateManager?
To fix CVE-2021-32008 in Secomea GateManager, it is recommended to update to Version 9.6.621421015 or later.