ID

VAR-202102-0392


CVE

CVE-2020-29022


TITLE

GateManager Web server  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2020-011438

DESCRIPTION

Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior to 9.3. GateManager Web server Contains an unspecified vulnerability.Information may be obtained. Secomea GateManager is a remote access server product of Secomea, Denmark

Trust: 2.16

sources: NVD: CVE-2020-29022 // JVNDB: JVNDB-2020-011438 // CNVD: CNVD-2021-18014

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-18014

AFFECTED PRODUCTS

vendor:secomeamodel:gatemanager 9250scope:eqversion:*

Trust: 1.0

vendor:secomeamodel:gatemanager 8250scope:ltversion:9.3

Trust: 1.0

vendor:secomeamodel:gatemanager 4260scope:eqversion:*

Trust: 1.0

vendor:secomeamodel:gatemanager 4250scope:eqversion:*

Trust: 1.0

vendor:b r industrial automationmodel:gatemanager 4250scope: - version: -

Trust: 0.8

vendor:b r industrial automationmodel:gatemanager 4260scope: - version: -

Trust: 0.8

vendor:b r industrial automationmodel:gatemanager 8250scope: - version: -

Trust: 0.8

vendor:b r industrial automationmodel:gatemanager 9250scope: - version: -

Trust: 0.8

vendor:secomeamodel:gatemanagerscope:ltversion:9.3

Trust: 0.6

sources: CNVD: CNVD-2021-18014 // JVNDB: JVNDB-2020-011438 // NVD: CVE-2020-29022

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-29022
value: MEDIUM

Trust: 1.0

VulnerabilityReporting@secomea.com: CVE-2020-29022
value: MEDIUM

Trust: 1.0

NVD: CVE-2020-29022
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2021-18014
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202102-1222
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2020-29022
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2021-18014
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-29022
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 1.4
version: 3.1

Trust: 2.0

NVD: CVE-2020-29022
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2021-18014 // JVNDB: JVNDB-2020-011438 // CNNVD: CNNVD-202102-1222 // NVD: CVE-2020-29022 // NVD: CVE-2020-29022

PROBLEMTYPE DATA

problemtype:CWE-159

Trust: 1.0

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-011438 // NVD: CVE-2020-29022

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202102-1222

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202102-1222

PATCH

title:RD-2923url:https://www.secomea.com/support/cybersecurity-advisory/#2923

Trust: 0.8

title:Patch for Secomea GateManager has unspecified vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/253281

Trust: 0.6

title:Sanitize and Secomea GateManager Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=142418

Trust: 0.6

sources: CNVD: CNVD-2021-18014 // JVNDB: JVNDB-2020-011438 // CNNVD: CNNVD-202102-1222

EXTERNAL IDS

db:NVDid:CVE-2020-29022

Trust: 3.0

db:JVNDBid:JVNDB-2020-011438

Trust: 0.8

db:CNVDid:CNVD-2021-18014

Trust: 0.6

db:CNNVDid:CNNVD-202102-1222

Trust: 0.6

sources: CNVD: CNVD-2021-18014 // JVNDB: JVNDB-2020-011438 // CNNVD: CNNVD-202102-1222 // NVD: CVE-2020-29022

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2020-29022

Trust: 2.0

url:https://www.secomea.com/support/cybersecurity-advisory/#2923

Trust: 1.6

sources: CNVD: CNVD-2021-18014 // JVNDB: JVNDB-2020-011438 // CNNVD: CNNVD-202102-1222 // NVD: CVE-2020-29022

SOURCES

db:CNVDid:CNVD-2021-18014
db:JVNDBid:JVNDB-2020-011438
db:CNNVDid:CNNVD-202102-1222
db:NVDid:CVE-2020-29022

LAST UPDATE DATE

2024-11-23T21:51:03.080000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-18014date:2021-03-16T00:00:00
db:JVNDBid:JVNDB-2020-011438date:2021-04-02T05:28:00
db:CNNVDid:CNNVD-202102-1222date:2021-03-09T00:00:00
db:NVDid:CVE-2020-29022date:2024-11-21T05:23:31.880

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-18014date:2021-03-16T00:00:00
db:JVNDBid:JVNDB-2020-011438date:2021-04-02T00:00:00
db:CNNVDid:CNNVD-202102-1222date:2021-02-16T00:00:00
db:NVDid:CVE-2020-29022date:2021-02-16T16:15:12.533