← back
CVE-2021-32002

SiteManager troubleshooter allows access without authentication from local network

CVSS 4.3 MEDIUMEPSS 0.2%CWE-200CWE-284
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.3EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
05 Aug 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Improper Access Control vulnerability in web service of Secomea SiteManager allows local attacker without credentials to gather network information and configuration of the SiteManager. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
Secomea · SiteManager

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →