ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.twcert.org.tw/tw/cp-132-5137-730a6-1.html |
History
No history.
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2021-09-30T10:41:06.633278Z
Updated: 2024-09-16T16:53:19.967Z
Reserved: 2021-09-15T00:00:00
Link: CVE-2021-41301
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-09-30T11:15:07.977
Modified: 2024-11-21T06:25:59.980
Link: CVE-2021-41301
Redhat
No data.