CVE Vulnerabilities

CVE-2021-41300

Insufficiently Protected Credentials

Published: Sep 30, 2021 | Modified: Oct 07, 2021
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Ecs_router_controller-ecs_firmware Ecoa - (including) - (including)

Potential Mitigations

References