Description
ECOA BAS controller has a Cross-Site Request Forgery vulnerability, thus authenticated attacker can remotely place a forged request at a malicious web page and execute CRUD commands (GET, POST, PUT, DELETE) to perform arbitrary operations in the system.
No analysis available yet.
Remediation
Vendor Solution
Contact tech support from ECOA.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-28325 | ECOA BAS controller has a Cross-Site Request Forgery vulnerability, thus authenticated attacker can remotely place a forged request at a malicious web page and execute CRUD commands (GET, POST, PUT, DELETE) to perform arbitrary operations in the system. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5131-c653b-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-17T00:52:20.343Z
Reserved: 2021-09-15T00:00:00.000Z
Link: CVE-2021-41295
No data.
Status : Modified
Published: 2021-09-30T11:15:07.653
Modified: 2024-11-21T06:25:59.177
Link: CVE-2021-41295
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD