First published: Wed May 04 2022(Updated: )
Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack connection. This issue affects: Secomea GateManager all versions prior to 9.7.
Credit: VulnerabilityReporting@secomea.com
Affected Software | Affected Version | How to fix |
---|---|---|
Secomea Gatemanager 4250 Firmware | <9.7.622134021 | |
Secomea GateManager | ||
Secomea Gatemanager | <9.7.622134021 | |
Secomea GateManager | ||
Secomea Gatemanager 8250 Firmware | <9.7.622134021 | |
Secomea Gatemanager 8250 Firmware | ||
Secomea GateManager | <9.7.622134021 | |
Secomea GateManager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-25787 is high with a severity value of 6.7.
The affected software for CVE-2022-25787 is Secomea GateManager all versions prior to 9.7.
CVE-2022-25787 allows system administrators to hijack connections through information exposure in the query strings of GET requests in the LMM API of Secomea GateManager.
The CWE ID assigned to CVE-2022-25787 is CWE-200, CWE-598.
You can find more information about CVE-2022-25787 on the Secomea website at https://www.secomea.com/support/cybersecurity-advisory/.