PT-2018-1715 · Laquis · Laquis Scada
B0Nd
·
Published
2018-07-10
·
Updated
2019-10-09
·
CVE-2018-17901
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
LAquis SCADA versions 4.1.0.3870 and prior
Description:
The issue is related to a buffer overflow in memory due to improper data recording. This can be exploited by an attacker using a specially crafted file, potentially allowing the execution of arbitrary code. The vulnerability is also related to the application's failure to sanitize user input when processing project files, which may enable an attacker to execute code under the current process.
Recommendations:
For LAquis SCADA versions 4.1.0.3870 and prior, consider restricting the processing of project files from untrusted sources until a patch is available.
As a temporary workaround, avoid using specially crafted files that could trigger the buffer overflow issue.
Restrict access to the
LQS File Parsing module to minimize the risk of exploitation.Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Laquis Scada