CVE-2020-29031: Secomea Gatemanager 4250 Firmware
High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.
An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c
Affected products
- Secomea Gatemanager 4250 Firmware: before 9.0i (fixed in 9.0i)
- Secomea Gatemanager 4260 Firmware: before 9.0i (fixed in 9.0i)
- Secomea Gatemanager 8250 Firmware: before 9.2c (fixed in 9.2c)
- Secomea Gatemanager 9250 Firmware: before 9.0i (fixed in 9.0i)
Published 2021-02-15. Last modified 2026-06-17.