Impact
A session fixation flaw in the webserver module of Secomea GateManager lets an attacker set a valid session identifier before user authentication. By forcing the application to accept a chosen session ID, the attacker can later impersonate the legitimate user, gaining unauthorized access to protected resources. The weakness is a classic example of CWE‑384, which can compromise confidentiality and integrity of user data. The impact extends to any user interacting with the affected GateManager instance, potentially allowing full administrative takeover if the session is granted elevated privileges.
Affected Systems
The vulnerability affects Secomea GateManager webserver module. Affected releases include GateManager 11.5.0 and GateManager 11.4.625515072.0. Versions 11.6 and 11.4.626194074 or any later release contain the patch and are not vulnerable.
Risk and Exploitability
The CVSS score of 8.3 classifies this flaw as high risk. The EPSS score is 0.00241, indicating a very low probability of exploitation, but the vulnerability is listed in external advisories and is not yet included in CISA’s KEV catalog. Based on the description, it is inferred that the flaw can be exploited through the web interface, where an attacker can craft a request to assign a session ID via URL or cookie. Successful exploitation requires the attacker to reach the application’s authentication flow; it does not need remote code execution or privileged access before the attack.
OpenCVE Enrichment