Record summary

CVE-2021-41291 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Manager, unauthenticated attackers can remotely disclose directory content on the affected device.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

7
ProductSourceVersion rangeStatus

ECS Router Controller ECS (FLASH)

Browse ECOA / ECS Router Controller ECS (FLASH)
CVE Listnext of 0unknown
CVE Listnext of 0unknown
CVE Listnext of 0unknown
CVE Listnext of 0unknown
CVE Listnext of 0unknown
CVE Listnext of 0unknown
CVE Listnext of 0unknown

Nuclei templates

1
ProjectDiscoveryHIGHECOA Building Automation System - Directory Traversal Content DisclosureCVSS 7.5

The ECOA BAS controller suffers from a directory traversal content disclosure vulnerability. Using the GET parameter cpath in File Manager (fmangersub), attackers can disclose directory content on the affected device

Impact

An attacker can exploit this vulnerability to access sensitive files and directories, potentially exposing sensitive information.

Remediation

Apply the latest security patches or updates provided by the vendor to fix the directory traversal vulnerability in the ECOA Building Automation System.

WeaknessesCWE-22
Authorsgy741
Template tagscve2021cveecoalfitraversalvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:ecoa:ecs_router_controller-ecs_firmware:-:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2