6.5

CVE-2017-6564

On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /download directory. This ability allows for an attacker to download sensitive system files from the host machine such as databases which contain information that can aid in further attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FranklinfuelingTs-550 Evo Firmware Version2.3.0.7332
   FranklinfuelingTs-550 Evo Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.82% 0.523
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

http://www.u235.io/single-post/2017/05/01/Penetrating-Fuel-Management-Systems
Third Party Advisory
URL Repurposed
Technical Description
https://gist.github.com/Stick-U235/b187931f828e92866d09b9bdeb956ca2
Third Party Advisory