« Volver al listado

CVE-2021-41300

Estado: ModificadaCrítica (9.8)—

ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-41300",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "twcert@cert.org.tw",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "twcert@cert.org.tw",
      "affectedData": [
        {
          "vendor": "ECOA",
          "product": "ECS Router Controller ECS (FLASH)",
          "versions": [
            {
              "status": "unknown",
              "version": "next of 0",
              "lessThan": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "ECOA",
          "product": "RiskBuster Terminator E6L45",
          "versions": [
            {
              "status": "unknown",
              "version": "next of 0",
              "lessThan": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "ECOA",
          "product": "RiskBuster System RB 3.0.0",
          "versions": [
            {
              "status": "unknown",
              "version": "next of 0",
              "lessThan": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "ECOA",
          "product": "RiskBuster System TRANE 1.0",
          "versions": [
            {
              "status": "unknown",
              "version": "next of 0",
              "lessThan": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "ECOA",
          "product": "Graphic Control Software",
          "versions": [
            {
              "status": "unknown",
              "version": "next of 0",
              "lessThan": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "ECOA",
          "product": "SmartHome II E9246",
          "versions": [
            {
              "status": "unknown",
              "version": "next of 0",
              "lessThan": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "ECOA",
          "product": "RiskTerminator",
          "versions": [
            {
              "status": "unknown",
              "version": "next of 0",
              "lessThan": "unspecified",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-09-30T11:15:07.923",
  "references": [
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-5136-3e315-1.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-5136-3e315-1.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "twcert@cert.org.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality."
    },
    {
      "lang": "es",
      "value": "La página especial del controlador ECOA BAS muestra la cuenta de usuario y las contraseñas en texto plano, por lo que unos atacantes no autenticados pueden acceder a la página y alcanzar privilegios con plena funcionalidad"
    }
  ],
  "lastModified": "2026-06-17T04:08:16.097",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:ecoa:ecs_router_controller-ecs_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E80292D1-E3AD-42B6-A63E-3546010B97A3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:ecoa:ecs_router_controller-ecs:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "541B6C82-F00E-4BFC-9947-A55B2F4EDD06"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:ecoa:riskbuster_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19A28430-AB2B-423F-82D4-FC0E3A6DF335"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:ecoa:riskbuster:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "58A6F2A4-A7DA-4A88-B572-917FFC80ADC1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ecoa:riskterminator:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "841DF575-8E63-4AB4-A6F9-77C28FC65BCE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "twcert@cert.org.tw"
}