PT-2018-1715 · Laquis · Laquis Scada

B0Nd

·

Published

2018-07-10

·

Updated

2019-10-09

·

CVE-2018-17901

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: LAquis SCADA versions 4.1.0.3870 and prior
Description: The issue is related to a buffer overflow in memory due to improper data recording. This can be exploited by an attacker using a specially crafted file, potentially allowing the execution of arbitrary code. The vulnerability is also related to the application's failure to sanitize user input when processing project files, which may enable an attacker to execute code under the current process.
Recommendations: For LAquis SCADA versions 4.1.0.3870 and prior, consider restricting the processing of project files from untrusted sources until a patch is available. As a temporary workaround, avoid using specially crafted files that could trigger the buffer overflow issue. Restrict access to the LQS File Parsing module to minimize the risk of exploitation.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01308
CVE-2018-17901
ZDI-18-1254
ZDI-18-1261
ZDI-18-1262

Affected Products

Laquis Scada