CVE-2020-29031
Estado: ModificadaAlta (8.1)—
An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.75%
- Percentil entre todas las CVEs puntuadas: 53
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-280
- CWE-269
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-29031",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "VulnerabilityReporting@secomea.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.2,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "VulnerabilityReporting@secomea.com",
"affectedData": [
{
"vendor": "Secomea",
"product": "GateManager",
"versions": [
{
"status": "affected",
"version": "All",
"lessThan": "9.2c",
"versionType": "custom"
}
]
}
]
}
],
"published": "2021-02-15T16:15:14.857",
"references": [
{
"url": "https://www.secomea.com/support/cybersecurity-advisory/#2920",
"tags": [
"Vendor Advisory"
],
"source": "VulnerabilityReporting@secomea.com"
},
{
"url": "https://www.secomea.com/support/cybersecurity-advisory/#2920",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "VulnerabilityReporting@secomea.com",
"description": [
{
"lang": "en",
"value": "CWE-280"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c"
},
{
"lang": "es",
"value": "Se presenta una vulnerabilidad de Referencia Directa a Objetos No Segura en la Interfaz de Usuario Web de GateManager que permite a un atacante autenticado restablecer la contraseña de cualquier usuario en su dominio o subdominio, por medio de una escalada de privilegios. Este problema afecta a todas las versiones de GateManager anteriores a 9.2c"
}
],
"lastModified": "2026-06-17T03:11:00.613",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:secomea:gatemanager_8250_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "961FED65-FA19-40DA-8DEB-5950D67FE5AA",
"versionEndExcluding": "9.2c"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:secomea:gatemanager_8250:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5089C475-2013-4DF6-AD1E-12F576ACAE8E"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:secomea:gatemanager_4250_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E1FB8107-437D-4900-BA64-2928E33A13C2",
"versionEndExcluding": "9.0i"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:secomea:gatemanager_4250:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0DB6136A-5440-4980-940D-CD178DC219B8"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:secomea:gatemanager_4260_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DE7495A8-DCDD-4CE8-9D32-85BC9C5A4288",
"versionEndExcluding": "9.0i"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:secomea:gatemanager_4260:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9B546E62-81BB-4ED8-87C9-41BD79484AD0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:secomea:gatemanager_9250_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1B1EB5FA-451C-45E2-8D5F-7E88995D06BF",
"versionEndExcluding": "9.0i"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:secomea:gatemanager_9250:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "68DE2092-2EA1-4D49-84EB-20BE2CD7B113"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "VulnerabilityReporting@secomea.com"
}