Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-44039

Опубликовано: 05 дек. 2022
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker can overwrite system files like [system.conf] and [passwd], this occurs because the insecure usage of "fopen" system function with the mode "wb" which allows overwriting file if exists. Overwriting files such as passwd, allows an attacker to escalate his privileges by planting backdoor user with root privilege or change root password.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:franklinfueling:colibri_firmware:1.9.22.8925:*:*:*:*:*:*:*

EPSS

Процентиль: 75%
0.00915
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-863
CWE-863

Связанные уязвимости

CVSS3: 9.8
github
больше 2 лет назад

Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker can overwrite system files like [system.conf] and [passwd], this occurs because the insecure usage of "fopen" system function with the mode "wb" which allows overwriting file if exists. Overwriting files such as passwd, allows an attacker to escalate his privileges by planting backdoor user with root privilege or change root password.

EPSS

Процентиль: 75%
0.00915
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-863
CWE-863