SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-7247

cgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows remote attackers to discover sensitive information (user names and password hashes) via the cmdWebGetConfiguration action in a…

MEDIUM 5.0EPSS 2.63%

Does this matter?

Lower severity and a low EPSS score (2.63%). Track it; it rarely justifies an emergency change on its own.

Description

cgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows remote attackers to discover sensitive information (user names and password hashes) via the cmdWebGetConfiguration action in a TSA_REQUEST.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
2.63% probability · 85th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
franklinfueling/ts-550 evo firmware · franklinfueling/ts-550 evo
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.