PT-2018-11299 · Circarlife · Circarlife Scada

Publicado

2018-06-22

·

Atualizado

2018-08-10

·

CVE-2018-12635

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions CirCarLife Scada version 4.2.4
Description The issue allows unauthorized upgrades through specific requests. This can be achieved by sending requests to the "html/upgrade.html" and "services/system/firmware.upgrade" API endpoints.
Recommendations For CirCarLife Scada version 4.2.4, restrict access to the "html/upgrade.html" and "services/system/firmware.upgrade" API endpoints to prevent unauthorized upgrades.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-12635

Produtos afetados

Circarlife Scada