PT-2019-9690 · Lcds · Lcds Laquis Scada
Esteban Ruiz
+1
·
Publicado
2019-01-19
·
Atualizado
2019-10-09
·
CVE-2018-18992
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LCDS Laquis SCADA versions prior to 4.1.0.4150
Description
The issue allows an attacker to execute remote code on the server due to improper sanitation of user input. This can be achieved through command injection vulnerabilities in various components of the LAquis SCADA Web Server, including the relatorioindividual TAG, acompanhamentotela TAGALTERE, acompanhamentotela PAGINA, and relatorioindividual TITULO.
Recommendations
For versions prior to 4.1.0.4150, update to version 4.1.0.4150 or later to resolve the issue.
As a temporary workaround, consider restricting access to the LAquis SCADA Web Server to minimize the risk of exploitation.
Avoid using user input in the affected components until the issue is resolved.
Correção
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Lcds Laquis Scada