PT-2018-13685 · Circontrol · Circontrol Open Charge Point Protocol

Published

2018-09-18

·

Updated

2019-10-03

·

CVE-2018-16669

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CIRCONTROL Open Charge Point Protocol (OCPP) versions prior to 1.5.0
Description An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) due to the storage of credentials in XML files. This allows an unprivileged user to access the admin credentials of the ocpp and circarlife panels by looking at the /services/config/config.xml file.
Recommendations For versions prior to 1.5.0, update to version 1.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the /services/config/config.xml file to prevent unauthorized users from obtaining the admin credentials.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16669

Affected Products

Circontrol Open Charge Point Protocol