Lucene search

K
cveIcscertCVE-2024-8497
HistorySep 25, 2024 - 1:15 a.m.

CVE-2024-8497

2024-09-2501:15:46
CWE-36
icscert
web.nvd.nist.gov
27
cve-2024-8497
franklin fueling systems
ts-550 evo
security vulnerability
administrator credentials
file read exploit

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS4

8.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:N/SI:N/VA:N/SA:N

AI Score

7.4

Confidence

High

EPSS

0

Percentile

9.6%

Franklin Fueling Systems TS-550 EVO versions prior to 2.26.4.8967 possess a file that can be read arbitrarily that could allow an attacker obtain administrator credentials.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "TS-550 EVO",
    "vendor": "Franklin Fueling Systems",
    "versions": [
      {
        "lessThan": "2.26.4.8967",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS4

8.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:N/SI:N/VA:N/SA:N

AI Score

7.4

Confidence

High

EPSS

0

Percentile

9.6%

Related for CVE-2024-8497