Impact
The flaw resides within the system configuration module of the Nefteprodukttekhnika BUK TS‑G Gas Station Automation System running on Linux. The module implements an improper authentication check (CWE‑287) that accepts any credentials, effectively bypassing user verification. This flaw allows an attacker to gain unauthorized administrative access and subsequently manipulate core functions of the gas station automation, potentially interfering with fuel dispensing, pricing, and monetary transactions.
Affected Systems
Affected are Linux installations of the BUK TS‑G Gas Station Automation System from version 2.9.1 through 2.10.2. The control of these versions is commonly deployed at fuel dispensing establishments. The vulnerability is specific to the mentioned versions and does not affect earlier releases.
Risk and Exploitability
The CVSS score of 9.3 reflects a severe impact with high potential for full system compromise. The EPSS score is <1%, indicating a low probability of exploitation in the broader threat landscape, yet the flaw is trivial to exploit once the target is identified because it requires only a simple HTTP request containing arbitrary credentials to the system’s authentication interface. The system is not listed in the CISA KEV catalog, so no known exploitation campaigns exist, but the straightforward attack vector may attract threat actors who can use the bypass to gain unwanted administrative control over the gas station’s operations, including dispensing, transaction processing, and safety monitoring.
OpenCVE Enrichment