CVE Vulnerabilities

CVE-2022-2752

Improper Authentication

Published: Dec 09, 2022 | Modified: Nov 07, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions.

This issue affects:

Secomea GateManager versions from 9.4 through 9.7.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Gatemanager Secomea 9.4 (including) 9.7 (including)

Potential Mitigations

References