Beveiligingsadvies

CVE-2021-41290

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-09-30 10:40:49
Laatst bijgewerkt 2024-09-16 22:25:25
Toegewezen door twcert
CVSS-score 9.8
Status PUBLISHED

Beschrijving

ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected device.