CVE-2013-7247 describes an information disclosure vulnerability in Franklin Fueling Systems TS-550 evo firmware versions prior to 2.4.0. Specifically, the cgi-bin/tsaws.cgi script allows unauthenticated remote attackers to retrieve sensitive information, including usernames and password hashes, through a crafted TSA_REQUEST. This vulnerability has a CVSS score of 5.0, indicating a medium severity, with a low attack complexity and no authentication required for exploitation, leading to a potential compromise of confidentiality. While there is an exploit available on ExploitDB, there is no evidence of active exploitation, Metasploit or Nuclei modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.0.6833CPE matchmatch criteria | cpe:2.3:o:franklinfueling:ts-550_evo_firmware:2.0.0.6833:*:*:*:*:*:*:* | ||
2.3.1.7492CPE matchmatch criteria | cpe:2.3:o:franklinfueling:ts-550_evo_firmware:2.3.1.7492:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:franklinfueling:ts-550_evo:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.