CVE-2020-29022 Vulnerability Details

  /     /     /  

CVE-2020-29022 Metadata Quick Info

CVE Published: 16/02/2021 | CVE Updated: 16/09/2024 | CVE Year: 2020
Source: Secomea | Vendor: Secomea | Product: GateManager
Status : PUBLISHED

CVE-2020-29022 Description

Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior to 9.3

Metrics

CVSS Version: 3.1 | Base Score: 5.3 MEDIUM
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* NONE
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* LOW
    Integrity Impact (I)* NONE
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID: CWE-159
CWE Name: CWE-159 Failure to Sanitize Special Element
Source: Secomea

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).