PT-2020-12250 · Lcds · Lcds Laquis Scada

Published

2020-04-30

·

Updated

2020-05-06

·

CVE-2020-10622

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LCDS LAquis SCADA versions 4.3.1 and prior
Description The affected product is vulnerable to arbitrary file creation by unauthorized users. This issue allows unauthorized users to create files arbitrarily, which could lead to security breaches.
Recommendations For versions 4.3.1 and prior, update to a version later than 4.3.1 to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the system to minimize the risk of exploitation. Restrict file creation capabilities to authorized users only until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10622
ZDI-20-576
ZDI-20-577

Affected Products

Lcds Laquis Scada