VulnerabilityModified
CVE-2021-32002
Improper Access Control vulnerability in web service of Secomea SiteManager allows local attacker without credentials to gather network information and configuration of the SiteManager.
LOW 3.3EPSS 0.23%
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
Improper Access Control vulnerability in web service of Secomea SiteManager allows local attacker without credentials to gather network information and configuration of the SiteManager. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.
- CVSS 3.1
- 3.3 LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.23% probability · 14th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-284
- Affected
- secomea/sitemanager firmware
- Source
- VulnerabilityReporting@secomea.com
References
- https://www.secomea.com/support/cybersecurity-advisoryVendor Advisory
- https://www.secomea.com/support/cybersecurity-advisoryVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.