Vulnerability Description
On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the roleDiag user, which can be obtained by exploiting CVE-2013-7247, has the ability to upload files to the server hosting the web service. As no sanitization checks are in place, an attacker can upload a malicious payload.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Franklinfueling | Ts-550 Evo Firmware | 2.3.0.7332 |
| Franklinfueling | Ts-550 Evo | - |
Related Weaknesses (CWE)
References
- http://www.u235.io/single-post/2017/05/01/Penetrating-Fuel-Management-SystemsTechnical DescriptionThird Party AdvisoryURL Repurposed
- https://gist.github.com/Stick-U235/b187931f828e92866d09b9bdeb956ca2Third Party Advisory
- http://www.u235.io/single-post/2017/05/01/Penetrating-Fuel-Management-SystemsTechnical DescriptionThird Party AdvisoryURL Repurposed
- https://gist.github.com/Stick-U235/b187931f828e92866d09b9bdeb956ca2Third Party Advisory
FAQ
What is CVE-2017-6565?
CVE-2017-6565 is a vulnerability with a CVSS score of 8.8 (HIGH). On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the roleDiag user, which can be obtained by exploiting CVE-2013-7247, has the ability to upload files to the server hosting the web service. ...
How severe is CVE-2017-6565?
CVE-2017-6565 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-6565?
Check the references section above for vendor advisories and patch information. Affected products include: Franklinfueling Ts-550 Evo Firmware, Franklinfueling Ts-550 Evo.