RULE(RULE ID:337776)

Rule General Information
Release Date: 2024-01-09
Rule Name: CIRCONTROL CirCarLife Information Disclosure Vulnerability (CVE-2018-16672)
Severity:
CVE ID:
Rule Protection Details
Description: An issue was discovered in CIRCONTROL CirCarLife before 4.3. Due to the storage of multiple sensitive information elements in a JSON format at /services/system/setup.json, an authenticated but unprivileged user can exfiltrate critical setup information.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, Others
Reference: ExploitDB:45384
https://github.com/SadFud/Exploits/tree/master/Real
Solutions
Refer to the announcement or patch by the vendor: https://circontrol.com/