CVE-2018-17918
9.8
CRITICAL · CVSS 3.0 · EPSS 3.8% (pctl 90)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a specific page.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.81% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-288 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-11-02 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| circontrol | circarlife |
| circontrol | circarlife firmware |
References
→ the Explorer · watch your stack · NVD