ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2021-09-30T10:41:06.633278Z

Updated: 2024-09-16T16:53:19.967Z

Reserved: 2021-09-15T00:00:00

Link: CVE-2021-41301

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-09-30T11:15:07.977

Modified: 2021-10-07T14:19:03.830

Link: CVE-2021-41301

cve-icon Redhat

No data.