CVE-2020-29022
Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior to 9.3
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.21%
- CWE
- CWE-159
- Published
- 2021-02-16
- Last modified
- 2026-03-14
Affected products
- Secomea GateManager
Weakness type
Related vulnerabilities
- CVE-2026-35536 — In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and...
- CVE-2026-29106 — SuiteCRM has blind XSS in return_id parameter
- CVE-2026-2636 — Denial of Service in Microsoft OS
- CVE-2025-61984 — ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain...
- CVE-2025-52884 — risc0-ethereum-contracts allows invalid commitment with digest value of zero to be accepted by Steel.validateCommitment
- CVE-2024-51500 — Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmware
- CVE-2021-21707 — Special characters break path parsing in XML functions
- CVE-2021-42375 — An incorrect handling of a special element in Busybox's ash applet leads to denial of service when...