RULE(RULE ID:337779)

Rule General Information
Release Date: 2024-01-09
Rule Name: CIRCONTROL CirCarLife Information Disclosure Vulnerability (CVE-2018-16670)
Severity:
CVE ID:
Rule Protection Details
Description: An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, Others
Reference: https://github.com/SadFud/Exploits/tree/master/Real
Solutions
Refer to the announcement or patch by the vendor: https://circontrol.com/