CVE-2018-16672: Circontrol Circarlife Scada

Medium severity, CVSS 6.5. EPSS: 1.7% chance of exploitation in the next 30 days.

An issue was discovered in CIRCONTROL CirCarLife before 4.3. Due to the storage of multiple sensitive information elements in a JSON format at /services/system/setup.json, an authenticated but unprivileged user can exfiltrate critical setup information.

Affected products

  • Circontrol Circarlife Scada: before 4.3 (fixed in 4.3)

Published 2018-09-26. Last modified 2026-06-17.