ZeroHour

CVE-2021-41300

CVSS 3.1
9.8 critical
EPSS
<1%p60
Published
()
Modified
Description

ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality.

Vendors
ecoa
Products
ecs router controller-ecs firmware, riskbuster firmware, riskterminator
Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.