RULE(RULE ID:337777)

Rule General Information
Release Date: 2024-01-09
Rule Name: CIRCONTROL CirCarLife Information Disclosure Vulnerability (CVE-2018-16669)
Severity:
CVE ID:
Rule Protection Details
Description: An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to storage of credentials in XML files, an unprivileged user can look at /services/config/config.xml for the admin credentials of the ocpp and circarlife panels.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, Others
Reference: ExploitDB:45384
https://github.com/SadFud/Exploits/tree/master/Real
Solutions
Refer to the announcement or patch by the vendor: https://circontrol.com/