Improper Authentication in GateManager - CVE-2020-29030
Published: February 23, 2021
GateManager
Secomea
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the authentication token is, by default, exposed in all future POST/GET requests once authenticated to the Gatemanager. A remote attacker can gain access to sensitive information, such as session identifiers and gain unauthorized access to the application.