CVE-2021-41291
ECOA BAS controller - Path Traversal-1
Record summary
CVE-2021-41291 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Manager, unauthenticated attackers can remotely disclose directory content on the affected device.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
7| Product | Source | Version range | Status |
|---|---|---|---|
ECS Router Controller ECS (FLASH)Browse ECOA / ECS Router Controller ECS (FLASH) | CVE List | next of 0 | unknown |
Graphic Control SoftwareBrowse ECOA / Graphic Control Software | CVE List | next of 0 | unknown |
RiskBuster System RB 3.0.0Browse ECOA / RiskBuster System RB 3.0.0 | CVE List | next of 0 | unknown |
RiskBuster System TRANE 1.0Browse ECOA / RiskBuster System TRANE 1.0 | CVE List | next of 0 | unknown |
RiskBuster Terminator E6L45Browse ECOA / RiskBuster Terminator E6L45 | CVE List | next of 0 | unknown |
RiskTerminatorBrowse ECOA / RiskTerminator | CVE List | next of 0 | unknown |
SmartHome II E9246Browse ECOA / SmartHome II E9246 | CVE List | next of 0 | unknown |
Nuclei templates
1ProjectDiscoveryHIGHECOA Building Automation System - Directory Traversal Content DisclosureCVSS 7.5
The ECOA BAS controller suffers from a directory traversal content disclosure vulnerability. Using the GET parameter cpath in File Manager (fmangersub), attackers can disclose directory content on the affected device
Impact
An attacker can exploit this vulnerability to access sensitive files and directories, potentially exposing sensitive information.
Remediation
Apply the latest security patches or updates provided by the vendor to fix the directory traversal vulnerability in the ECOA Building Automation System.
Source: ProjectDiscovery