← Back to CVE List

CVE-2021-41292

Published: 2021-09-30T11:15Z
Last Modified: 2024-11-21T06:25Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical access controls in smart homes and buildings and manipulate HVAC. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt