CVE-2021-41298
ECOA BAS controller - Improper Access Control
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers with general user's privilege can remotely bypass authorization and access the hidden resources in the system and execute privileged functionalities.
El controlador ECOA BAS es vulnerable a las referencias directas a objetos no seguro que se producen cuando la aplicaciĆ³n proporciona acceso directo a objetos basados en la entrada suministrada por el usuario. Como resultado de esta vulnerabilidad, unos atacantes con privilegio de usuario general pueden omitir la autorizaciĆ³n de forma remota y acceder a los recursos ocultos del sistema y ejecutar funcionalidades privilegiadas
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-09-15 CVE Reserved
- 2021-09-30 CVE Published
- 2023-04-23 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://www.twcert.org.tw/tw/cp-132-5134-39f74-1.html | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ecoa Search vendor "Ecoa" | Ecs Router Controller-ecs Firmware Search vendor "Ecoa" for product "Ecs Router Controller-ecs Firmware" | - | - |
Affected
| in | Ecoa Search vendor "Ecoa" | Ecs Router Controller-ecs Search vendor "Ecoa" for product "Ecs Router Controller-ecs" | - | - |
Safe
|
Ecoa Search vendor "Ecoa" | Riskbuster Firmware Search vendor "Ecoa" for product "Riskbuster Firmware" | - | - |
Affected
| in | Ecoa Search vendor "Ecoa" | Riskbuster Search vendor "Ecoa" for product "Riskbuster" | - | - |
Safe
|
Ecoa Search vendor "Ecoa" | Riskterminator Search vendor "Ecoa" for product "Riskterminator" | - | - |
Affected
|