CVE-2024-8497
- EPSS 0.47%
- Veröffentlicht 25.09.2024 01:15:46
- Zuletzt bearbeitet 26.09.2024 13:32:02
Franklin Fueling Systems TS-550 EVO versions prior to 2.26.4.8967 possess a file that can be read arbitrarily that could allow an attacker obtain administrator credentials.
CVE-2023-5846
- EPSS 0.03%
- Veröffentlicht 02.11.2023 17:15:11
- Zuletzt bearbeitet 21.11.2024 08:42:37
Franklin Fueling System TS-550 versions prior to 1.9.23.8960 are vulnerable to attackers decoding admin credentials, resulting in unauthenticated access to the device.
CVE-2021-46420
- EPSS 3.25%
- Veröffentlicht 27.04.2022 11:15:44
- Zuletzt bearbeitet 21.11.2024 06:34:03
Franklin Fueling Systems FFS TS-550 evo 2.23.4.8936 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.
CVE-2021-46421
- EPSS 3.25%
- Veröffentlicht 27.04.2022 11:15:44
- Zuletzt bearbeitet 21.11.2024 06:34:03
Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.
CVE-2017-6564
- EPSS 0.18%
- Veröffentlicht 01.05.2017 19:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /download directory. This ability allows for an attacker to download sensitiv...
CVE-2017-6565
- EPSS 0.25%
- Veröffentlicht 01.05.2017 19:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the roleDiag user, which can be obtained by exploiting CVE-2013-7247, has the ability to upload files to the server hosting the web service. As no sanitization checks are in place, an attacke...
- EPSS 17.25%
- Veröffentlicht 26.01.2014 01:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
cgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows remote attackers to discover sensitive information (user names and password hashes) via the cmdWebGetConfiguration action in a TS...
- EPSS 15.4%
- Veröffentlicht 26.01.2014 01:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 has a hardcoded password for the roleDiag account, which allows remote attackers to gain root privileges, as demonstrated using a cmdWebCheckRole action in a...