Description


ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files deletion. Using the specific GET parameter, unauthenticated attackers can remotely delete arbitrary files on the affected device and cause denial of service scenario.

Weaknesses



CWE-22

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

9.1 · Critical

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-09-30T09:15:07.600Z

4 years ago

Last modified

2024-11-21T05:25:59.047Z

1 year ago