An issue exists in CIRCONTROL CirCarLife prior to 4.3. Due to the storage of multiple sensitive information elements in a JSON format at /services/system/setup.json, an authenticated but unprivileged user can exfiltrate critical setup information.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
circontrol circarlife scada |