Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wf48-98rg-498v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical access controls in smart homes and buildings and manipulate HVAC.

ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical access controls in smart homes and buildings and manipulate HVAC.

EPSS

Процентиль: 53%
0.00307
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-287
CWE-288

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical access controls in smart homes and buildings and manipulate HVAC.

EPSS

Процентиль: 53%
0.00307
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-287
CWE-288