10
CVSSv2

CVE-2021-41301

Published: 30/09/2021 Updated: 07/10/2021
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated malicious user to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ecoa ecs_router_controller-ecs_firmware -

ecoa riskbuster_firmware -

ecoa riskterminator -