PT-2022-27088 · Franklin Fueling Systems · Ffs Colibri

Cyber Guy

+1

·

Published

2022-12-05

·

Updated

2022-12-07

·

CVE-2022-44039

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Franklin Fueling System FFS Colibri version 1.9.22.8925
Description The issue allows an attacker to overwrite system files, such as system.conf and passwd, due to the insecure usage of the fopen system function with the mode wb, which allows overwriting files if they exist. This can enable an attacker to escalate privileges by planting a backdoor user with root privilege or changing the root password.
Recommendations For Franklin Fueling System FFS Colibri version 1.9.22.8925, consider disabling the use of the fopen system function with the mode wb until a patch is available to prevent the overwriting of system files. Restrict access to sensitive files such as system.conf and passwd to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-44039

Affected Products

Ffs Colibri