PT-2022-27088 · Franklin Fueling Systems · Ffs Colibri
Cyber Guy
+1
·
Published
2022-12-05
·
Updated
2022-12-07
·
CVE-2022-44039
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Franklin Fueling System FFS Colibri version 1.9.22.8925
Description
The issue allows an attacker to overwrite system files, such as
system.conf and passwd, due to the insecure usage of the fopen system function with the mode wb, which allows overwriting files if they exist. This can enable an attacker to escalate privileges by planting a backdoor user with root privilege or changing the root password.Recommendations
For Franklin Fueling System FFS Colibri version 1.9.22.8925, consider disabling the use of the
fopen system function with the mode wb until a patch is available to prevent the overwriting of system files. Restrict access to sensitive files such as system.conf and passwd to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ffs Colibri