ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the unauthenticated attacker can remotely query user password and obtain user’s privilege.
Fixes

Solution

Contact tech support from ECOA.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-09-16T20:21:36.719Z

Reserved: 2021-09-15T00:00:00

Link: CVE-2021-41302

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-09-30T11:15:08.033

Modified: 2024-11-21T06:26:00.130

Link: CVE-2021-41302

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.