CVE-2021-41292
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
30/09/2021
Last modified:
25/04/2022
Description
ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical access controls in smart homes and buildings and manipulate HVAC.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:ecoa:ecs_router_controller-ecs_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:ecoa:ecs_router_controller-ecs:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:ecoa:riskbuster_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:ecoa:riskbuster:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:ecoa:riskterminator:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page