ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-28331 | ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access. |
Fixes
Solution
Contact tech support from ECOA.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5137-730a6-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T16:53:19.967Z
Reserved: 2021-09-15T00:00:00
Link: CVE-2021-41301
No data.
Status : Modified
Published: 2021-09-30T11:15:07.977
Modified: 2024-11-21T06:25:59.980
Link: CVE-2021-41301
No data.
OpenCVE Enrichment
No data.
EUVD