Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown
CVE-2021-41300
Disclosure Date: September 30, 2021 (last updated February 23, 2025)
ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality.
0
Attacker Value
Unknown
CVE-2021-41301
Disclosure Date: September 30, 2021 (last updated February 23, 2025)
ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access.
0
Attacker Value
Unknown
CVE-2021-41298
Disclosure Date: September 30, 2021 (last updated February 23, 2025)
ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers with general user's privilege can remotely bypass authorization and access the hidden resources in the system and execute privileged functionalities.
0