ECOA records
13 published records for vendor ecoa.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-522 Insufficiently Protected Credentials2
- CWE-288 Authentication Bypass Using an Alternate Path or Channel1
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2021-41291Proof of concept | ECOA BAS controller - Path Traversal-1ecoa · ecs router controller-ecs firmware · CWE-22 | High7.5 | — | 82.7% | Sep 30, 2021 |
40Plan | CVE-2021-41290No exploit | ECOA BAS controller - Path Traversal-1ecoa · ecs router controller-ecs firmware · CWE-434 | Critical9.8 | — | 2.3% | Sep 30, 2021 |
40Plan | CVE-2021-41299No exploit | ECOA BAS controller - Use of Hard-coded Credentialsecoa · ecs router controller-ecs firmware · CWE-798 | Critical9.8 | — | 2.1% | Sep 30, 2021 |
40Plan | CVE-2021-41301No exploit | ECOA BAS controller - Exposure of Sensitive Information to an Unauthorized Actorecoa · ecs router controller-ecs firmware · CWE-200 | Critical9.8 | — | 2.0% | Sep 30, 2021 |
39Monitor | CVE-2021-41300No exploit | ECOA BAS controller - Insufficiently Protected Credentials-2ecoa · ecs router controller-ecs firmware · CWE-522 | Critical9.8 | — | 1.0% | Sep 30, 2021 |
39Monitor | CVE-2021-41296No exploit | ECOA BAS controller - Weak Password Requirementsecoa · ecs router controller-ecs firmware · CWE-521 | Critical9.8 | — | 1.0% | Sep 30, 2021 |
36Monitor | CVE-2021-41293Proof of concept | ECOA BAS controller - Path Traversal-3ecoa · ecs router controller-ecs firmware · CWE-22 | High7.5 | — | 19.9% | Sep 30, 2021 |
36Monitor | CVE-2021-41294No exploit | ECOA BAS controller - Path Traversal-4ecoa · ecs router controller-ecs firmware · CWE-22 | Critical9.1 | — | 1.2% | Sep 30, 2021 |
36Monitor | CVE-2021-41292No exploit | ECOA BAS controller - Broken Authenticationecoa · ecs router controller-ecs firmware · CWE-288 | Critical9.1 | — | 1.2% | Sep 30, 2021 |
35Monitor | CVE-2021-41298No exploit | ECOA BAS controller - Improper Access Controlecoa · ecs router controller-ecs firmware · CWE-284 | High8.8 | — | 0.9% | Sep 30, 2021 |
35Monitor | CVE-2021-41297No exploit | ECOA BAS controller - Insufficiently Protected Credentials-1ecoa · ecs router controller-ecs firmware · CWE-522 | High8.8 | — | 0.7% | Sep 30, 2021 |
35Monitor | CVE-2021-41295No exploit | ECOA BAS controller - Cross-Site Request Forgery (CSRF)ecoa · ecs router controller-ecs firmware · CWE-352 | High8.8 | — | 0.4% | Sep 30, 2021 |
29Monitor | CVE-2021-41302No exploit | ECOA BAS controller - Missing Encryption of Sensitive Dataecoa · ecs router controller-ecs firmware · CWE-311 | High7.3 | — | 0.4% | Sep 30, 2021 |
- CVE-2021-4129155Plan
ECOA BAS controller - Path Traversal-1
HighCVSS 7.5Proof of conceptEPSS 83%ecoa · ecs router controller-ecs firmwareSep 30, 2021
- CVE-2021-4129040Plan
ECOA BAS controller - Path Traversal-1
CriticalCVSS 9.8No exploitEPSS 2%ecoa · ecs router controller-ecs firmwareSep 30, 2021
- CVE-2021-4129940Plan
ECOA BAS controller - Use of Hard-coded Credentials
CriticalCVSS 9.8No exploitEPSS 2%ecoa · ecs router controller-ecs firmwareSep 30, 2021
- CVE-2021-4130140Plan
ECOA BAS controller - Exposure of Sensitive Information to an Unauthorized Actor
CriticalCVSS 9.8No exploitEPSS 2%ecoa · ecs router controller-ecs firmwareSep 30, 2021
- CVE-2021-4130039Monitor
ECOA BAS controller - Insufficiently Protected Credentials-2
CriticalCVSS 9.8No exploitEPSS 1%ecoa · ecs router controller-ecs firmwareSep 30, 2021
- CVE-2021-4129639Monitor
ECOA BAS controller - Weak Password Requirements
CriticalCVSS 9.8No exploitEPSS 1%ecoa · ecs router controller-ecs firmwareSep 30, 2021
- CVE-2021-4129336Monitor
ECOA BAS controller - Path Traversal-3
HighCVSS 7.5Proof of conceptEPSS 20%ecoa · ecs router controller-ecs firmwareSep 30, 2021
- CVE-2021-4129436Monitor
ECOA BAS controller - Path Traversal-4
CriticalCVSS 9.1No exploitEPSS 1%ecoa · ecs router controller-ecs firmwareSep 30, 2021
- CVE-2021-4129236Monitor
ECOA BAS controller - Broken Authentication
CriticalCVSS 9.1No exploitEPSS 1%ecoa · ecs router controller-ecs firmwareSep 30, 2021
- CVE-2021-4129835Monitor
ECOA BAS controller - Improper Access Control
HighCVSS 8.8No exploitEPSS 1%ecoa · ecs router controller-ecs firmwareSep 30, 2021
- CVE-2021-4129735Monitor
ECOA BAS controller - Insufficiently Protected Credentials-1
HighCVSS 8.8No exploitEPSS 1%ecoa · ecs router controller-ecs firmwareSep 30, 2021
- CVE-2021-4129535Monitor
ECOA BAS controller - Cross-Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%ecoa · ecs router controller-ecs firmwareSep 30, 2021
- CVE-2021-4130229Monitor
ECOA BAS controller - Missing Encryption of Sensitive Data
HighCVSS 7.3No exploitEPSS 0%ecoa · ecs router controller-ecs firmwareSep 30, 2021