OFF-BY-ONE ERROR CWE-193
Description
GateManager versions prior to 9.2c, The affected product is vulnerable to an off-by-one error, which may allow an attacker to remotely execute arbitrary code or cause a denial-of-service condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An off-by-one error in Secomea GateManager prior to 9.2c allows a remote unauthenticated attacker to execute arbitrary code or cause a denial-of-service.
Vulnerability
An off-by-one error (CWE-193) exists in Secomea GateManager versions prior to 9.2c. The vulnerability can be triggered by sending a specially crafted request to the affected service, potentially allowing an attacker to overwrite adjacent memory boundaries [1].
Exploitation
To exploit this vulnerability, an attacker needs network access to the GateManager instance. No authentication is required, but the attack complexity is rated as high (AV:N/AC:H) [1]. The attacker must carefully craft a network packet that induces an off-by-one write, likely requiring trial and error or reverse engineering to succeed.
Impact
Successful exploitation can lead to remote code execution in the context of the affected process or a denial-of-service condition. While the CVSS vector indicates high impact to confidentiality, integrity, and availability, the exact scope is limited to the affected system (no scope change) [1]. The vulnerability is rated CVSS v3 base score 8.1.
Mitigation
The vendor, Secomea, has released version 9.2c which addresses this vulnerability. Users should update to 9.2c or later immediately [1]. No workarounds are documented. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <9.2c
- Range: All versions prior to 9.2c
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- us-cert.cisa.gov/ics/advisories/icsa-20-210-01mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.