Description
ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers with general user's privilege can remotely bypass authorization and access the hidden resources in the system and execute privileged functionalities.
Related CPE's
Vulnerable
Vulnerable
Vulnerable
References
https://www.twcert.org.tw/tw/cp-132-5134-39f74-1.html
Third Party Advisory
https://www.twcert.org.tw/tw/cp-132-5134-39f74-1.html
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.8 · High
Information
Source identifier
Vulnerability status
Modified
Published
2021-09-30T09:15:07.813Z
4 years agoLast modified
2024-11-21T05:25:59.567Z
1 year ago