ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical access controls in smart homes and buildings and manipulate HVAC.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2021-09-30T10:40:52.625489Z

Updated: 2024-09-17T03:32:30.239Z

Reserved: 2021-09-15T00:00:00

Link: CVE-2021-41292

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-09-30T11:15:07.477

Modified: 2022-04-25T17:59:48.587

Link: CVE-2021-41292

cve-icon Redhat

No data.