漏洞描述
The ECOA BAS controller suffers from a directory traversal content disclosure vulnerability. Using the GET parameter cpath in File Manager (fmangersub), attackers can disclose directory content on the affected device
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-41291↗www.zeroscience.mkhttps://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5670.php↗www.twcert.org.twhttps://www.twcert.org.tw/en/cp-139-5140-6343c-2.html↗www.twcert.org.twhttps://www.twcert.org.tw/tw/cp-132-5127-3cbd3-1.html↗github.comhttps://github.com/ARPSyndicate/cvemon↗