PT-2019-9693 · Lcds · Lcds Laquis Scada

Esteban Ruiz

+1

·

Publicado

2019-01-19

·

Atualizado

2019-10-09

·

CVE-2018-18996

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LCDS Laquis SCADA versions prior to 4.1.0.4150
Description The issue allows an attacker to execute remote code on the server due to improper authorization or sanitation of user input. This can be achieved through command injection in certain parameters, such as relatorionome TAG, relatorionome TITULO, and relatorionome NOME.
Recommendations For versions prior to 4.1.0.4150, update to version 4.1.0.4150 or later to resolve the issue. As a temporary workaround, consider restricting access to the affected parameters relatorionome TAG, relatorionome TITULO, and relatorionome NOME to minimize the risk of exploitation.

Correção

Special Elements Injection

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18996
ZDI-19-064
ZDI-19-065
ZDI-19-066

Produtos afetados

Lcds Laquis Scada