#VU15712 Authentication bypass in CirCarLife - CVE-2018-17918

 

#VU15712 Authentication bypass in CirCarLife - CVE-2018-17918

Published: November 1, 2018 / Updated: November 5, 2018


Vulnerability identifier: #VU15712
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2018-17918
CWE-ID: CWE-288
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
CirCarLife
Software vendor:
Circontrol

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to authentication bypass when using alternative path or channel. A remote unauthenticated attacker can trick the victim into visiting a specially crafted website, bypass authentication and execute arbitrary code with elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Update to version 4.3.1.

External links