Vulnerabilities > CVE-2017-6564 - Missing Authorization vulnerability in Franklinfueling Ts-550 EVO Firmware 2.3.0.7332

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
franklinfueling
CWE-862

Summary

On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /download directory. This ability allows for an attacker to download sensitive system files from the host machine such as databases which contain information that can aid in further attacks.

Vulnerable Configurations

Part Description Count
OS
Franklinfueling
1
Hardware
Franklinfueling
1

Common Weakness Enumeration (CWE)