ID

VAR-201705-3686


CVE

CVE-2017-6565


TITLE

Franklin Fueling Systems TS-550 evo Device access control vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2017-003717

DESCRIPTION

On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the roleDiag user, which can be obtained by exploiting CVE-2013-7247, has the ability to upload files to the server hosting the web service. As no sanitization checks are in place, an attacker can upload a malicious payload. Franklin Fueling Systems TS-550 evo is a fuel management system from Franklin Fueling Systems in the United States. The system is used to monitor fuel storage and provides an intuitive and easy-to-read interface for alarm functions. A security vulnerability exists in Franklin Fueling Systems TS-550 evo version 2.3.0.7332

Trust: 1.71

sources: NVD: CVE-2017-6565 // JVNDB: JVNDB-2017-003717 // VULHUB: VHN-114768

AFFECTED PRODUCTS

vendor:franklinfuelingmodel:ts-550 evoscope:eqversion:2.3.0.7332

Trust: 1.6

vendor:franklin fuelingmodel:ts-550 evoscope:eqversion:2.3.0.7332

Trust: 0.8

sources: JVNDB: JVNDB-2017-003717 // CNNVD: CNNVD-201703-388 // NVD: CVE-2017-6565

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-6565
value: HIGH

Trust: 1.0

NVD: CVE-2017-6565
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201703-388
value: HIGH

Trust: 0.6

VULHUB: VHN-114768
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-6565
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-114768
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-6565
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-114768 // JVNDB: JVNDB-2017-003717 // CNNVD: CNNVD-201703-388 // NVD: CVE-2017-6565

PROBLEMTYPE DATA

problemtype:CWE-862

Trust: 1.1

problemtype:CWE-284

Trust: 0.9

sources: VULHUB: VHN-114768 // JVNDB: JVNDB-2017-003717 // NVD: CVE-2017-6565

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201703-388

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201703-388

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-003717

PATCH

title:TS-550 evo & TS-5000 evourl:http://www.franklinfueling.com/americas/fms/featured/1697/en/ts-550-evo-ts-5000-evo#Highlights

Trust: 0.8

sources: JVNDB: JVNDB-2017-003717

EXTERNAL IDS

db:NVDid:CVE-2017-6565

Trust: 2.5

db:JVNDBid:JVNDB-2017-003717

Trust: 0.8

db:CNNVDid:CNNVD-201703-388

Trust: 0.7

db:VULHUBid:VHN-114768

Trust: 0.1

sources: VULHUB: VHN-114768 // JVNDB: JVNDB-2017-003717 // CNNVD: CNNVD-201703-388 // NVD: CVE-2017-6565

REFERENCES

url:http://www.u235.io/single-post/2017/05/01/penetrating-fuel-management-systems

Trust: 2.5

url:https://gist.github.com/stick-u235/b187931f828e92866d09b9bdeb956ca2

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-6565

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-6565

Trust: 0.8

sources: VULHUB: VHN-114768 // JVNDB: JVNDB-2017-003717 // CNNVD: CNNVD-201703-388 // NVD: CVE-2017-6565

SOURCES

db:VULHUBid:VHN-114768
db:JVNDBid:JVNDB-2017-003717
db:CNNVDid:CNNVD-201703-388
db:NVDid:CVE-2017-6565

LAST UPDATE DATE

2025-04-20T23:25:02.535000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-114768date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2017-003717date:2017-06-05T00:00:00
db:CNNVDid:CNNVD-201703-388date:2019-10-23T00:00:00
db:NVDid:CVE-2017-6565date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:VULHUBid:VHN-114768date:2017-05-01T00:00:00
db:JVNDBid:JVNDB-2017-003717date:2017-06-05T00:00:00
db:CNNVDid:CNNVD-201703-388date:2017-03-10T00:00:00
db:NVDid:CVE-2017-6565date:2017-05-01T19:59:00.207