Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2018-17922
Disclosure Date: November 02, 2018 (last updated November 27, 2024)
Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible without authentication.
0
Attacker Value
Unknown
CVE-2018-17918
Disclosure Date: November 02, 2018 (last updated November 27, 2024)
Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a specific page.
0
Attacker Value
Unknown
CVE-2018-16672
Disclosure Date: September 26, 2018 (last updated November 27, 2024)
An issue was discovered in CIRCONTROL CirCarLife before 4.3. Due to the storage of multiple sensitive information elements in a JSON format at /services/system/setup.json, an authenticated but unprivileged user can exfiltrate critical setup information.
0
Attacker Value
Unknown
CVE-2018-16668
Disclosure Date: September 18, 2018 (last updated November 27, 2024)
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the lack of authentication for /html/repository.
0
Attacker Value
Unknown
CVE-2018-16670
Disclosure Date: September 18, 2018 (last updated November 27, 2024)
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html.
0
Attacker Value
Unknown
CVE-2018-16671
Disclosure Date: September 18, 2018 (last updated November 27, 2024)
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is system software information disclosure due to lack of authentication for /html/device-id.
0
Attacker Value
Unknown
CVE-2018-16669
Disclosure Date: September 18, 2018 (last updated November 27, 2024)
An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to storage of credentials in XML files, an unprivileged user can look at /services/config/config.xml for the admin credentials of the ocpp and circarlife panels.
0
Attacker Value
Unknown
CVE-2018-12635
Disclosure Date: June 22, 2018 (last updated November 26, 2024)
CirCarLife Scada v4.2.4 allows unauthorized upgrades via requests to the html/upgrade.html and services/system/firmware.upgrade URIs.
0
Attacker Value
Unknown
CVE-2018-12634
Disclosure Date: June 22, 2018 (last updated November 26, 2024)
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI.
0