PT-2019-9693 · Lcds · Lcds Laquis Scada

Esteban Ruiz

+1

·

Published

2019-01-19

·

Updated

2019-10-09

·

CVE-2018-18996

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LCDS Laquis SCADA versions prior to 4.1.0.4150
Description The issue allows an attacker to execute remote code on the server due to improper authorization or sanitation of user input. This can be achieved through command injection in certain parameters, such as relatorionome TAG, relatorionome TITULO, and relatorionome NOME.
Recommendations For versions prior to 4.1.0.4150, update to version 4.1.0.4150 or later to resolve the issue. As a temporary workaround, consider restricting access to the affected parameters relatorionome TAG, relatorionome TITULO, and relatorionome NOME to minimize the risk of exploitation.

Fix

Special Elements Injection

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-18996
ZDI-19-064
ZDI-19-065
ZDI-19-066

Affected Products

Lcds Laquis Scada