Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ecoa riskterminator - vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2021-41295
ECOA BAS controller has a Cross-Site Request Forgery vulnerability, thus authenticated attacker can remotely place a forged request at a malicious web page and execute CRUD commands (GET, POST, PUT, DELETE) to perform arbitrary operations in the system.
Ecoa Ecs Router Controller-ecs Firmware -
Ecoa Riskbuster Firmware -
Ecoa Riskterminator -
8.8
CVSSv3
CVE-2021-41298
ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers with general user's privilege can remotely bypass authorization...
Ecoa Ecs Router Controller-ecs Firmware -
Ecoa Riskbuster Firmware -
Ecoa Riskterminator -
7.3
CVSSv3
CVE-2021-41302
ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the unauthenticated attacker can remotely query user password and obtain user’s privilege.
Ecoa Ecs Router Controller-ecs Firmware -
Ecoa Riskbuster Firmware -
Ecoa Riskterminator -
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23316
SQL injection
type confusion
CVE-2024-20697
CVE-2024-4344
local
CVE-2024-30043
CVE-2024-3821
CVE-2024-5041
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2