Vulnerabilities > CVE-2021-41301 - Authorization Bypass Through User-Controlled Key vulnerability in Ecoa products

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access.

Vulnerable Configurations

Part Description Count
OS
Ecoa
2
Hardware
Ecoa
2
Application
Ecoa
1