5
CVSSv2

CVE-2021-41293

Published: 30/09/2021 Updated: 07/10/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. Using the specific POST parameter, unauthenticated attackers can remotely disclose arbitrary files on the affected device and disclose sensitive and system information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ecoa ecs_router_controller-ecs_firmware -

ecoa riskbuster_firmware -

ecoa riskterminator -