PT-2019-9690 · Lcds · Lcds Laquis Scada

Esteban Ruiz

+1

·

Published

2019-01-19

·

Updated

2019-10-09

·

CVE-2018-18992

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LCDS Laquis SCADA versions prior to 4.1.0.4150
Description The issue allows an attacker to execute remote code on the server due to improper sanitation of user input. This can be achieved through command injection vulnerabilities in various components of the LAquis SCADA Web Server, including the relatorioindividual TAG, acompanhamentotela TAGALTERE, acompanhamentotela PAGINA, and relatorioindividual TITULO.
Recommendations For versions prior to 4.1.0.4150, update to version 4.1.0.4150 or later to resolve the issue. As a temporary workaround, consider restricting access to the LAquis SCADA Web Server to minimize the risk of exploitation. Avoid using user input in the affected components until the issue is resolved.

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-18992
ZDI-19-059
ZDI-19-061
ZDI-19-062
ZDI-19-063

Affected Products

Lcds Laquis Scada