PT-2019-9690 · Lcds · Lcds Laquis Scada
Esteban Ruiz
+1
·
Published
2019-01-19
·
Updated
2019-10-09
·
CVE-2018-18992
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LCDS Laquis SCADA versions prior to 4.1.0.4150
Description
The issue allows an attacker to execute remote code on the server due to improper sanitation of user input. This can be achieved through command injection vulnerabilities in various components of the LAquis SCADA Web Server, including the relatorioindividual TAG, acompanhamentotela TAGALTERE, acompanhamentotela PAGINA, and relatorioindividual TITULO.
Recommendations
For versions prior to 4.1.0.4150, update to version 4.1.0.4150 or later to resolve the issue.
As a temporary workaround, consider restricting access to the LAquis SCADA Web Server to minimize the risk of exploitation.
Avoid using user input in the affected components until the issue is resolved.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lcds Laquis Scada