ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.twcert.org.tw/tw/cp-132-5137-730a6-1.html |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T16:53:19.967Z
Reserved: 2021-09-15T00:00:00
Link: CVE-2021-41301

No data.

Status : Modified
Published: 2021-09-30T11:15:07.977
Modified: 2024-11-21T06:25:59.980
Link: CVE-2021-41301

No data.