VulnerabilityModified
CVE-2021-32003
Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning.
MEDIUM 5.5EPSS 0.23%
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.23% probability · 14th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-523, CWE-522
- Affected
- secomea/sitemanager firmware
- Source
- VulnerabilityReporting@secomea.com
References
- https://www.secomea.com/support/cybersecurity-advisoryVendor Advisory
- https://www.secomea.com/support/cybersecurity-advisoryVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.