PT-2022-12693 · Franklin Fueling Systems · Colibri Controller Module
Published
2022-04-07
·
Updated
2022-04-13
·
CVE-2021-46417
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Franklin Fueling Systems Colibri Controller Module version 1.8.19.8580
Description
The issue is related to insecure handling of a download function, which leads to disclosure of internal files due to path traversal with root privileges.
Recommendations
For Franklin Fueling Systems Colibri Controller Module version 1.8.19.8580, consider restricting access to the download function to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Colibri Controller Module