CVE-2021-41293
ECOA BAS controller - Path Traversal-3
Record summary
CVE-2021-41293 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. Using the specific POST parameter, unauthenticated attackers can remotely disclose arbitrary files on the affected device and disclose sensitive and system information.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 22, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
8| Product | Source | Version range | Status |
|---|---|---|---|
ECS Router Controller ECS (FLASH)Browse ECOA / ECS Router Controller ECS (FLASH) | CVE List | next of 0 | unknown |
Graphic Control SoftwareBrowse ECOA / Graphic Control Software | CVE List | next of 0 | unknown |
RiskBuster System RB 3.0.0Browse ECOA / RiskBuster System RB 3.0.0 | CVE List | next of 0 | unknown |
RiskBuster System TRANE 1.0Browse ECOA / RiskBuster System TRANE 1.0 | CVE List | next of 0 | unknown |
RiskBuster Terminator E6L45Browse ECOA / RiskBuster Terminator E6L45 | CVE List | next of 0 | unknown |
RiskTerminatorBrowse ECOA / RiskTerminator | CVE List | next of 0 | unknown |
SmartHome II E9246Browse ECOA / SmartHome II E9246 | CVE List | next of 0 | unknown |
ecs_router_controller-ecs_firmwareBrowse ecoa / ecs_router_controller-ecs_firmware | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHECOA Building Automation System - Arbitrary File RetrievalCVSS 7.5
The ECOA BAS controller suffers from an arbitrary file disclosure vulnerability. Using the 'fname' POST parameter in viewlog.jsp, attackers can disclose arbitrary files on the affected device and disclose sensitive and system information.
Impact
Unauthenticated attackers can read arbitrary files from the ECOA BAS controller including /etc/passwd via path traversal in the fname parameter, potentially exposing sensitive system configuration and credentials.
Remediation
Apply the latest security patches or updates provided by the vendor to fix the arbitrary file retrieval vulnerability in the ECOA Building Automation System.
Source: ProjectDiscovery