CVE-2022-25780: Information leak via device availability query function
Information Exposure vulnerability in web UI of Secomea GateManager allows logged in user to query devices outside own scope.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-25780?
CVE-2022-25780 is an Information Exposure vulnerability in the web UI of Secomea GateManager that allows a logged-in user to query devices outside their own scope.
Which version of Secomea GateManager firmware is affected by CVE-2022-25780?
Secomea GateManager firmware versions up to 9.7.622134021 are affected by CVE-2022-25780.
What is the severity rating of CVE-2022-25780?
CVE-2022-25780 has a severity rating of 4.3 (medium).
How can I fix CVE-2022-25780?
To fix CVE-2022-25780, it is recommended to update your Secomea GateManager firmware to a version higher than 9.7.622134021.
Where can I find more information about CVE-2022-25780?
You can find more information about CVE-2022-25780 in the Secomea cybersecurity advisory at the following link: [https://www.secomea.com/support/cybersecurity-advisory/](https://www.secomea.com/support/cybersecurity-advisory/)