CVE-2018-17922
9.8
CRITICAL · CVSS 3.0 · EPSS 3.2% (pctl 88)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible without authentication.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.25% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-522 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-11-02 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| circontrol | circarlife |
| circontrol | circarlife firmware |
References
→ the Explorer · watch your stack · NVD