CVE-2020-29022: fallo de gravedad media en Secomea GateManager
Host Header Injection allowing web cache poisoning attacks
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.3epss 0.8%
probabilidad de explotación
0.8%top 44% de las CVE
explotación observada
noninguna fuente lo reporta
Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior to 9.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Productos afectados
Secomea · GateManagerCVEs relacionadas — Secomea GateManager
En el mismo producto, de las más peligrosas a las menos.
CVE-2020-14510CRITICALOFF-BY-ONE ERROR CWE-193EPSS 2.5%CVE-2020-14508HIGHOFF-BY-ONE ERROR CWE-193EPSS 2.0%CVE-2020-29026CRITICALCVE-2020-29026EPSS 1.5%CVE-2021-32008CRITICALLogged-in Administrator may get unrestricted file system accessEPSS 1.0%CVE-2020-14512HIGHUSE OF PASSWORD HASH WITH INSUFFICIENT COMPUTATIONAL EFFORT CWE-916EPSS 0.8%CVE-2022-38123HIGHInsufficient validation of plugin filesEPSS 0.8%