HIGH · 10.0

CVE-2013-7248

Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 has a hardcoded password for the roleDiag account, which allows remote attackers to gain root privileges, a...

Vulnerability Description

Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 has a hardcoded password for the roleDiag account, which allows remote attackers to gain root privileges, as demonstrated using a cmdWebCheckRole action in a TSA_REQUEST.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
FranklinfuelingTs-550 Evo Firmware2.0.0.6833
FranklinfuelingTs-550 Evo-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-7248?

CVE-2013-7248 is a vulnerability with a CVSS score of 10.0 (HIGH). Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 has a hardcoded password for the roleDiag account, which allows remote attackers to gain root privileges, a...

How severe is CVE-2013-7248?

CVE-2013-7248 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-7248?

Check the references section above for vendor advisories and patch information. Affected products include: Franklinfueling Ts-550 Evo Firmware, Franklinfueling Ts-550 Evo.