CVE-2020-29022
Summary
| CVE | CVE-2020-29022 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-16 16:15:00 UTC |
| Updated | 2021-02-26 18:58:00 UTC |
| Description | Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior to 9.3 |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Secomea | Gatemanager 4250 | - | All | All | All |
| Hardware | Secomea | Gatemanager 4250 | - | All | All | All |
| Operating System | Secomea | Gatemanager 4250 Firmware | All | All | All | All |
| Operating System | Secomea | Gatemanager 4250 Firmware | All | All | All | All |
| Hardware | Secomea | Gatemanager 4260 | - | All | All | All |
| Hardware | Secomea | Gatemanager 4260 | - | All | All | All |
| Operating System | Secomea | Gatemanager 4260 Firmware | All | All | All | All |
| Operating System | Secomea | Gatemanager 4260 Firmware | All | All | All | All |
| Hardware | Secomea | Gatemanager 8250 | - | All | All | All |
| Hardware | Secomea | Gatemanager 8250 | - | All | All | All |
| Operating System | Secomea | Gatemanager 8250 Firmware | All | All | All | All |
| Operating System | Secomea | Gatemanager 8250 Firmware | All | All | All | All |
| Hardware | Secomea | Gatemanager 9250 | - | All | All | All |
| Hardware | Secomea | Gatemanager 9250 | - | All | All | All |
| Operating System | Secomea | Gatemanager 9250 Firmware | All | All | All | All |
| Operating System | Secomea | Gatemanager 9250 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cybersecurity Advisory - Secomea | MISC | www.secomea.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.