Impact
An improper handling of insufficient permissions or privileges in Secomea GateManager exposes users with lower privileges to gain elevated access, resulting in unauthorized configuration changes or system control. The flaw is a classic privilege escalation weakness, identified as CWE-280, allowing an attacker to ascend hierarchies without legitimate authorization.
Affected Systems
Secomea GateManager versions 11.5 and 11.4.625515072 are vulnerable. The vulnerability is fixed in releases 11.6 and 11.4.626194074 and later. Devices running older revisions must be updated to avoid exploitation.
Risk and Exploitability
The CVSS rating of 6.5 indicates a moderate severity. EPSS score is < 1%, indicating a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Likely, exploitation requires initial access to the GateManager interface with an account that has limited permissions. The attacker can then leverage the permission bypass to obtain higher privileges, potentially compromising the entire system. No public exploit is known, but the moderate severity warrants prompt remediation.
OpenCVE Enrichment