🔙 목록으로 돌아가기

CVE-2018-16668: CirCarLife <4.3 - Improper Authentication

TitleCirCarLife <4.3 - Improper Authentication
Authorgeeknik
SeverityMedium
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to sensitive data, compromising the confidentiality and integrity of the system.
RemediationUpgrade CirCarLife to version 4.3 or higher to fix the improper authentication issue.
CVSS Score5.3
EPSS Score0.43027
CVE IDCVE-2018-16668
CWE IDCWE-287
Tags cve cve2018 circarlife scada iot disclosure edb circontrol vuln

🔍 Vulnerability Description

CirCarLife before 4.3 is susceptible to improper authentication. An internal installation path disclosure exists due to the lack of authentication for /html/repository.System. An attacker can obtain sensitive information, modify data, and/or execute unauthorized operations.

🌐 HTTP Request

GET /html/repository HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.7 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-16668.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-16668.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A