Executive brief
Secomea GateManager is a secure remote access solution used to protect industrial and critical infrastructure operations. A session fixation vulnerability in its web interface allows an attacker to hijack user sessions and gain unauthorized access to the device, potentially leading to complete compromise of protected systems and operations.
Technical details
This is a session fixation vulnerability in the webserver module of Secomea GateManager that allows an attacker to force a user to use a known session identifier. The vulnerability affects versions 11.5.0 and 11.4.625515072. An attacker can exploit this by tricking a user into accessing a malicious link containing a pre-generated session ID, and if the application does not regenerate the session ID upon authentication, the attacker can then use the same session ID to gain unauthorized access. The vulnerability has been patched in version 11.6 and later, as well as in version 11.4.626194074 and above.
Affected products
- Secomea GateManager 11.5.0, 11.4.625515072
Timeline
- 2026-09-15: disclosed