Show filters
73 Total Results
Displaying 31-40 of 73
Sort by:
Attacker Value
Unknown

CVE-2018-16669

Disclosure Date: September 18, 2018 (last updated November 27, 2024)
An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to storage of credentials in XML files, an unprivileged user can look at /services/config/config.xml for the admin credentials of the ocpp and circarlife panels.
0
Attacker Value
Unknown

CVE-2018-12635

Disclosure Date: June 22, 2018 (last updated November 26, 2024)
CirCarLife Scada v4.2.4 allows unauthorized upgrades via requests to the html/upgrade.html and services/system/firmware.upgrade URIs.
0
Attacker Value
Unknown

CVE-2018-12634

Disclosure Date: June 22, 2018 (last updated November 26, 2024)
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI.
Attacker Value
Unknown

CVE-2018-11652

Disclosure Date: June 01, 2018 (last updated November 26, 2024)
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.
0
Attacker Value
Unknown

CVE-2017-12095

Disclosure Date: April 05, 2018 (last updated November 26, 2024)
An exploitable vulnerability exists in the WiFi Access Point feature of Circle with Disney running firmware 2.0.1. A series of WiFi packets can force Circle to setup an Access Point with default credentials. An attacker needs to send a series of spoofed "de-auth" packets to trigger this vulnerability.
0
Attacker Value
Unknown

CVE-2017-12094

Disclosure Date: November 07, 2017 (last updated November 26, 2024)
An exploitable vulnerability exists in the WiFi Channel parsing of Circle with Disney running firmware 2.0.1. A specially crafted SSID can cause the device to execute arbitrary sed commands. An attacker needs to setup an access point reachable by the device to trigger this vulnerability.
0
Attacker Value
Unknown

CVE-2017-2890

Disclosure Date: November 07, 2017 (last updated November 26, 2024)
An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an OS command injection. An attacker can send an HTTP request trigger this vulnerability.
Attacker Value
Unknown

CVE-2017-2913

Disclosure Date: November 07, 2017 (last updated November 26, 2024)
An exploitable vulnerability exists in the filtering functionality of Circle with Disney. SSL certificates for specific domain names can cause the Bluecoat library to accept a different certificate than intended. An attacker can host an HTTPS server with this certificate to trigger this vulnerability.
Attacker Value
Unknown

CVE-2017-2884

Disclosure Date: November 07, 2017 (last updated November 26, 2024)
An exploitable vulnerability exists in the user photo update functionality of Circle with Disney running firmware 2.0.1. A repeated set of specially crafted API calls can cause the device to corrupt essential memory, resulting in a bricked device. An attacker needs network connectivity to the device to trigger this vulnerability.
Attacker Value
Unknown

CVE-2017-2914

Disclosure Date: November 07, 2017 (last updated November 26, 2024)
An exploitable authentication bypass vulnerability exists in the API daemon of Circle with Disney running firmware 2.0.1. A specially crafted token can bypass the authentication routine of the Apid binary, causing the device to grant unintended administrative access. An attacker needs network connectivity to the device to trigger this vulnerability.