CVE-2022-38124

Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:secomea:sitemanager_1129_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_1129:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:secomea:sitemanager_3329_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_3329:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:secomea:sitemanager_1529_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_1529:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:secomea:sitemanager_3529_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_3529:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:secomea:sitemanager_1139_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_1139:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:secomea:sitemanager_3339_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_3339:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:secomea:sitemanager_1539_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_1539:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:secomea:sitemanager_3539_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_3539:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:secomea:sitemanager_1149_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_1149:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:secomea:sitemanager_3349_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_3349:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:secomea:sitemanager_1549_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_1549:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:secomea:sitemanager_3549_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_3549:-:*:*:*:*:*:*:*

History

16 Dec 2022, 05:02

Type Values Removed Values Added
References (MISC) https://www.secomea.com/support/cybersecurity-advisory/ - (MISC) https://www.secomea.com/support/cybersecurity-advisory/ - Vendor Advisory
First Time Secomea sitemanager 3349 Firmware
Secomea sitemanager 1539
Secomea sitemanager 3549 Firmware
Secomea
Secomea sitemanager 1549
Secomea sitemanager 1139
Secomea sitemanager 1149
Secomea sitemanager 3539 Firmware
Secomea sitemanager 1129
Secomea sitemanager 3529 Firmware
Secomea sitemanager 3349
Secomea sitemanager 1129 Firmware
Secomea sitemanager 1529
Secomea sitemanager 1149 Firmware
Secomea sitemanager 3339 Firmware
Secomea sitemanager 1539 Firmware
Secomea sitemanager 3529
Secomea sitemanager 3329
Secomea sitemanager 1549 Firmware
Secomea sitemanager 3329 Firmware
Secomea sitemanager 3339
Secomea sitemanager 1139 Firmware
Secomea sitemanager 3549
Secomea sitemanager 1529 Firmware
Secomea sitemanager 3539
CWE CWE-269
CPE cpe:2.3:o:secomea:sitemanager_1549_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:secomea:sitemanager_3339_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:secomea:sitemanager_1149_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_1549:-:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_3549:-:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_3339:-:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_1539:-:*:*:*:*:*:*:*
cpe:2.3:o:secomea:sitemanager_3529_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:secomea:sitemanager_3549_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:secomea:sitemanager_3539_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_3539:-:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_1529:-:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_1129:-:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_3329:-:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_3349:-:*:*:*:*:*:*:*
cpe:2.3:o:secomea:sitemanager_3349_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:secomea:sitemanager_1529_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:secomea:sitemanager_1129_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_1139:-:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_3529:-:*:*:*:*:*:*:*
cpe:2.3:o:secomea:sitemanager_1539_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:secomea:sitemanager_3329_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:secomea:sitemanager_1139_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:secomea:sitemanager_1149:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

13 Dec 2022, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-13 14:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-38124

Mitre link : CVE-2022-38124

CVE.ORG link : CVE-2022-38124


JSON object : View

Products Affected

secomea

  • sitemanager_1549
  • sitemanager_3549_firmware
  • sitemanager_3539_firmware
  • sitemanager_3539
  • sitemanager_3339_firmware
  • sitemanager_1539_firmware
  • sitemanager_3529_firmware
  • sitemanager_1529_firmware
  • sitemanager_3329
  • sitemanager_1549_firmware
  • sitemanager_1139
  • sitemanager_3329_firmware
  • sitemanager_1149
  • sitemanager_1539
  • sitemanager_3339
  • sitemanager_3349_firmware
  • sitemanager_1529
  • sitemanager_3549
  • sitemanager_1139_firmware
  • sitemanager_1129_firmware
  • sitemanager_1149_firmware
  • sitemanager_3529
  • sitemanager_3349
  • sitemanager_1129
CWE
CWE-269

Improper Privilege Management

CWE-267

Privilege Defined With Unsafe Actions