V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2022-25783
CVE
Medium

Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries without logging. Th…

CVSS
4.3
Medium
EPSS
0.00
p45
Published
2022-01-01
Updated
2022-01-01
Description

Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries without logging. This issue affects: Secomea GateManager versions prior to 9.7.

Tags · CWE
CWE-778
Affected products
Gatemanager_4250_firmwareGatemanager_4260_firmwareGatemanager_8250_firmwareGatemanager_9250_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Timeline
2022-01-01
Published
2022-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.002 · p45
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
gatemanager_4250_firmware*Tracked
gatemanager_4260_firmware*Tracked
gatemanager_8250_firmware*Tracked
gatemanager_9250_firmware*Tracked
Source databases
CVE