CVE-2022-44039
Last modified
CVE-2022-44039 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). EPSS estimates a 1.00% chance of exploitation in the next 30 days.
Description
Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker can overwrite system files like [system.conf] and [passwd], this occurs because the insecure usage of "fopen" system function with the mode "wb" which allows overwriting file if exists. Overwriting files such as passwd, allows an attacker to escalate his privileges by planting backdoor user with root privilege or change root password.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Franklinfueling | Colibri Firmware | 1.9.22.8925 |
References
- https://pastebin.com/raw/64stbsWuExploit, Third Party Advisory
- https://pastebin.com/raw/64stbsWuExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-44039?
How severe is CVE-2022-44039?
How do I fix CVE-2022-44039?
Are you affected by CVE-2022-44039?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
