Executive brief
Secomea GateManager, a central management platform for industrial remote access, contains a security flaw in its web server modules. This vulnerability allows an authenticated user to bypass certain security checks, potentially leading to unauthorized access to sensitive information. Such an exploit could compromise the confidentiality of industrial control network configurations and operational data.
Technical details
An improper authentication vulnerability (CWE-287) exists within the webserver modules of Secomea GateManager version 11.4;0. The flaw allows a remote attacker with low-level privileges to bypass authentication mechanisms. By exploiting this issue, an attacker can gain unauthorized access to data (Confidentiality: High) without affecting system integrity or availability. The attack vector is network-based and requires no user interaction, though it does require a baseline level of existing authentication (PR:L). Secomea addresses these vulnerabilities through standard product releases and hosted solution updates.
Affected products
- Secomea GateManager 11.4;0
Timeline
- 2026-03-19: disclosed: Initial NVD publication date
- 2026-03-19: advisory: Secomea cybersecurity advisory published