PT-2022-12693 · Franklin Fueling Systems · Colibri Controller Module

Published

2022-04-07

·

Updated

2022-04-13

·

CVE-2021-46417

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Franklin Fueling Systems Colibri Controller Module version 1.8.19.8580
Description The issue is related to insecure handling of a download function, which leads to disclosure of internal files due to path traversal with root privileges.
Recommendations For Franklin Fueling Systems Colibri Controller Module version 1.8.19.8580, consider restricting access to the download function to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-46417

Affected Products

Colibri Controller Module