Security Advisory

CVE-2021-41295

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-09-30 10:40:57
Last updated 2024-09-17 00:52:20
Assigner twcert
CVSS score 8.8
State PUBLISHED

Description

ECOA BAS controller has a Cross-Site Request Forgery vulnerability, thus authenticated attacker can remotely place a forged request at a malicious web page and execute CRUD commands (GET, POST, PUT, DELETE) to perform arbitrary operations in the system.