Back to overview

CVE-2021-32008

CRITICAL
9.9
CVSS 3.1
Description
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.

Metadata

CVE ID
CVE-2021-32008
State
PUBLISHED
Assigner
Secomea
Reserved
2021-05-03 00:00 UTC
Published
2022-03-04 21:20 UTC
Last updated
2024-08-03 23:17 UTC
Primary CWE
CWE-552
CWE-552 Files or Directories Accessible to External Parties
Vendor / Product
Secomea / GateManager
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
Secomea GateManager All ≤ 9.6.621421014
Weakness (CWE)
CWESourceDescription
CWE-22 cna CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-552 cna CWE-552 Files or Directories Accessible to External Parties
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview