SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-41293

ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure.

HIGH 7.5EPSS 19.9%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 19.9%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. Using the specific POST parameter, unauthenticated attackers can remotely disclose arbitrary files on the affected device and disclose sensitive and system information.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
19.87% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
ecoa/ecs router controller-ecs firmware · ecoa/riskbuster firmware · ecoa/riskterminator
Source
twcert@cert.org.tw

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.