Record summary

CVE-2021-41293 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. Using the specific POST parameter, unauthenticated attackers can remotely disclose arbitrary files on the affected device and disclose sensitive and system information.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

8
ProductSourceVersion rangeStatus

ECS Router Controller ECS (FLASH)

Browse ECOA / ECS Router Controller ECS (FLASH)
CVE Listnext of 0unknown
CVE Listnext of 0unknown
CVE Listnext of 0unknown
CVE Listnext of 0unknown
CVE Listnext of 0unknown
CVE Listnext of 0unknown
CVE Listnext of 0unknown

ecs_router_controller-ecs_firmware

Browse ecoa / ecs_router_controller-ecs_firmware
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHECOA Building Automation System - Arbitrary File RetrievalCVSS 7.5

The ECOA BAS controller suffers from an arbitrary file disclosure vulnerability. Using the 'fname' POST parameter in viewlog.jsp, attackers can disclose arbitrary files on the affected device and disclose sensitive and system information.

Impact

Unauthenticated attackers can read arbitrary files from the ECOA BAS controller including /etc/passwd via path traversal in the fname parameter, potentially exposing sensitive system configuration and credentials.

Remediation

Apply the latest security patches or updates provided by the vendor to fix the arbitrary file retrieval vulnerability in the ECOA Building Automation System.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2021cveecoalfidisclosurevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:ecoa:ecs_router_controller-ecs_firmware:-:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2