PT-2021-23246 · Unknown · Ecoa Bas Controller

Gjoko Krstic

·

Published

2021-09-30

·

Updated

2022-04-25

·

CVE-2021-41292

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ECOA BAS controller (affected versions not specified)
Description The ECOA BAS controller is affected by an authentication bypass issue. An unauthenticated attacker can exploit this by using cookie poisoning to remotely bypass authentication. This allows the attacker to disclose sensitive information, circumvent physical access controls in smart homes and buildings, and manipulate HVAC systems.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41292

Affected Products

Ecoa Bas Controller