{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-10-02T06:20:56.644","vulnerabilities":[{"cve":{"id":"CVE-2020-29026","sourceIdentifier":"VulnerabilityReporting@secomea.com","published":"2021-02-15T16:15:14.527","lastModified":"2026-06-17T03:11:00.080","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with administrative permissions to read and write arbitrary files in the Linux file system. This issue affects: GateManager all versions prior to 9.2c."},{"lang":"es","value":"Se presenta una vulnerabilidad de salto de directorio en la función file upload del GateManager que permite a un atacante autenticado con permisos administrativos leer y escribir archivos arbitrarios en el sistema de archivos de Linux.&#xa0;Este problema afecta a: GateManager todas las versiones anteriores a 9.2c"}],"affected":[{"source":"VulnerabilityReporting@secomea.com","affectedData":[{"vendor":"Secomea","product":"GateManager","versions":[{"version":"All","lessThan":"9.2c","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"VulnerabilityReporting@secomea.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L","baseScore":9.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.3,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"VulnerabilityReporting@secomea.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:secomea:gatemanager_8250_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"9.2c","matchCriteriaId":"961FED65-FA19-40DA-8DEB-5950D67FE5AA"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:secomea:gatemanager_8250:-:*:*:*:*:*:*:*","matchCriteriaId":"5089C475-2013-4DF6-AD1E-12F576ACAE8E"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:secomea:gatemanager_4250_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"9.0i","matchCriteriaId":"E1FB8107-437D-4900-BA64-2928E33A13C2"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:secomea:gatemanager_4250:-:*:*:*:*:*:*:*","matchCriteriaId":"0DB6136A-5440-4980-940D-CD178DC219B8"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:secomea:gatemanager_4260_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"9.0i","matchCriteriaId":"DE7495A8-DCDD-4CE8-9D32-85BC9C5A4288"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:secomea:gatemanager_4260:-:*:*:*:*:*:*:*","matchCriteriaId":"9B546E62-81BB-4ED8-87C9-41BD79484AD0"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:secomea:gatemanager_9250_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"9.0i","matchCriteriaId":"1B1EB5FA-451C-45E2-8D5F-7E88995D06BF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:secomea:gatemanager_9250:-:*:*:*:*:*:*:*","matchCriteriaId":"68DE2092-2EA1-4D49-84EB-20BE2CD7B113"}]}]}],"references":[{"url":"https://www.secomea.com/support/cybersecurity-advisory/#2918","source":"VulnerabilityReporting@secomea.com","tags":["Vendor Advisory"]},{"url":"https://www.secomea.com/support/cybersecurity-advisory/#2918","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}