VYPR
Unrated severityNVD Advisory· Published Aug 25, 2020· Updated Sep 16, 2024

OFF-BY-ONE ERROR CWE-193

CVE-2020-14508

Description

GateManager versions prior to 9.2c, The affected product is vulnerable to an off-by-one error, which may allow an attacker to remotely execute arbitrary code or cause a denial-of-service condition.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An off-by-one error in Secomea GateManager prior to 9.2c allows a remote unauthenticated attacker to execute arbitrary code or cause a denial-of-service.

Vulnerability

An off-by-one error (CWE-193) exists in Secomea GateManager versions prior to 9.2c. The vulnerability can be triggered by sending a specially crafted request to the affected service, potentially allowing an attacker to overwrite adjacent memory boundaries [1].

Exploitation

To exploit this vulnerability, an attacker needs network access to the GateManager instance. No authentication is required, but the attack complexity is rated as high (AV:N/AC:H) [1]. The attacker must carefully craft a network packet that induces an off-by-one write, likely requiring trial and error or reverse engineering to succeed.

Impact

Successful exploitation can lead to remote code execution in the context of the affected process or a denial-of-service condition. While the CVSS vector indicates high impact to confidentiality, integrity, and availability, the exact scope is limited to the affected system (no scope change) [1]. The vulnerability is rated CVSS v3 base score 8.1.

Mitigation

The vendor, Secomea, has released version 9.2c which addresses this vulnerability. Users should update to 9.2c or later immediately [1]. No workarounds are documented. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.