Back

HIGH

ECOA BAS controller - Path Traversal-1

Published Sep 30, 2021

Description

ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Manager, unauthenticated attackers can remotely disclose directory content on the affected device.

Affected products

Remediation

Vendor solution

Contact tech support from ECOA.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner twcert
Published Sep 30, 2021
Updated Sep 16, 2024
Reserved Sep 15, 2021

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner twcert
Published Sep 30, 2021
Updated Sep 16, 2024

GitHub

No data