CVE-2021-41292
Summary
| CVE | CVE-2021-41292 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-30 11:15:00 UTC |
| Updated | 2022-04-25 17:59:00 UTC |
| Description | ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical access controls in smart homes and buildings and manipulate HVAC. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ecoa | Ecs Router Controller-ecs | - | All | All | All |
| Operating System | Ecoa | Ecs Router Controller-ecs Firmware | - | All | All | All |
| Hardware | Ecoa | Riskbuster | - | All | All | All |
| Operating System | Ecoa | Riskbuster Firmware | - | All | All | All |
| Application | Ecoa | Riskterminator | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TWCERT/CC台灣電腦網路危機處理暨協調中心-ECOA BAS controller - Broken Authentication | MISC | www.twcert.org.tw | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.