VulnerabilityModified
CVE-2018-16670
There is PLC status disclosure due to lack of authentication for /html/devstat.html.
MEDIUM 5.3EPSS 24.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 24.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 24.57% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- circontrol/circarlife scada
- Source
- cve@mitre.org
References
- https://github.com/SadFud/Exploits/tree/master/Real%20World/Suites/cir-pwn-lifeThird Party Advisory
- https://www.exploit-db.com/exploits/45384/Exploit, Third Party Advisory, VDB Entry
- https://github.com/SadFud/Exploits/tree/master/Real%20World/Suites/cir-pwn-lifeThird Party Advisory
- https://www.exploit-db.com/exploits/45384/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.