Franklin Fueling Systems TS-550 EVO

View CSAF

1. EXECUTIVE SUMMARY

  • CVSS v4 8.7
  • ATTENTION: Exploitable remotely/low attack complexity
  • Vendor: Franklin Fueling Systems
  • Equipment: TS-550 EVO Automatic Tank Gauge
  • Vulnerability: Absolute Path Traversal

2. RISK EVALUATION

Successful exploitation of this vulnerability allow an attacker to gain administrative access over the affected device.

3. TECHNICAL DETAILS

3.1 AFFECTED PRODUCTS

The following Franklin Fueling Systems products are affected:

  • TS-550 EVO: Versions prior to 2.26.4.8967

3.2 Vulnerability Overview

3.2.1 ABSOLUTE PATH TRAVERSAL CWE-36

Franklin Fueling Systems TS-550 EVO versions prior to 2.26.4.8967 possess a file that can be read arbitrarily that could allow an attacker obtain administrator credentials.

CVE-2024-8497 has been assigned to this vulnerability. A CVSS v3.1 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

A CVSS v4 score has also been calculated for CVE-2024-8497. A base score of 8.7 has been calculated; the CVSS vector string is (CVSS4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N).

3.3 BACKGROUND

  • CRITICAL INFRASTRUCTURE SECTORS: Energy
  • COUNTRIES/AREAS DEPLOYED: Worldwide
  • COMPANY HEADQUARTERS LOCATION: United States

3.4 RESEARCHER

Pedro Umbelino of Bitsight reported this vulnerability to CISA.

Content was cut in order to protect the source.Please visit the source for the rest of the article.

This article has been indexed from All CISA Advisories

Read the original article: