Vulnerability Details CVE-2021-41300
ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 60.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 5.0
Products affected by CVE-2021-41300
-
cpe:2.3:a:ecoa:riskterminator:-
-
cpe:2.3:h:ecoa:ecs_router_controller-ecs:-
-
cpe:2.3:h:ecoa:riskbuster:-
-
cpe:2.3:o:ecoa:ecs_router_controller-ecs_firmware:-
-
cpe:2.3:o:ecoa:riskbuster_firmware:-