PT-2019-9687 · Lcds · Lcds Laquis Scada

Esteban Ruiz

+1

·

Publicado

2019-01-19

·

Atualizado

2019-10-09

·

CVE-2018-18988

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LCDS Laquis SCADA versions prior to 4.1.0.4150
Description The issue allows execution of script code by opening a specially crafted report format file, which may lead to remote code execution, data exfiltration, or cause a system crash. Multiple vulnerabilities have been identified in the LAquis SCADA LGX Report, including path traversal, information disclosure, remote code execution, and arbitrary file creation.
Recommendations For versions prior to 4.1.0.4150, update to version 4.1.0.4150 or later to resolve the issue. As a temporary workaround, consider restricting the opening of report format files from untrusted sources until a patch is available. Avoid using the LGX Report feature until the issue is resolved. Restrict access to the LGX Report module to minimize the risk of exploitation. Consider disabling the ShellExecute function and other vulnerable functions until a patch is available. At the moment, there is no other information about additional mitigation measures for this vulnerability.

Correção

RCE

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18988
ZDI-19-069
ZDI-19-070
ZDI-19-071
ZDI-19-072
ZDI-19-073
ZDI-19-074
ZDI-19-075
ZDI-19-076
ZDI-19-077
ZDI-19-078
ZDI-19-079
ZDI-19-080
ZDI-19-081
ZDI-19-082
ZDI-19-083
ZDI-19-084
ZDI-19-085
ZDI-19-086
ZDI-19-087
ZDI-19-088
ZDI-19-089
ZDI-19-090
ZDI-19-091
ZDI-19-092
ZDI-19-093
ZDI-19-094
ZDI-19-095
ZDI-19-096

Produtos afetados

Lcds Laquis Scada