Back

CRITICAL

ECOA BAS controller - Exposure of Sensitive Information to an Unauthorized Actor

Published Sep 30, 2021

Description

ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access.

Affected products

Remediation

Vendor solution

Contact tech support from ECOA.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Sep 30, 2021
Updated Sep 16, 2024
Reserved Sep 15, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner twcert
Published Sep 30, 2021
Updated Sep 16, 2024
Exploited since n/a
EUVD-2021-28331