PT-2023-9498 · Unknown · Laquis Scada

Natnael Samson

·

Published

2023-11-15

·

Updated

2024-05-22

·

CVE-2024-5040

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LAquis SCADA (affected versions not specified)
Description The issue is related to the LAquis SCADA system, where an attacker can access locations outside of their own directory. This is due to incorrect restriction of the path name to a directory with limited access. Exploitation of this issue may allow an attacker to read, modify, or delete data, or execute arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-07897
CVE-2024-5040
ZDI-24-484
ZDI-24-485
ZDI-24-486
ZDI-24-487
ZDI-24-488
ZDI-24-489
ZDI-24-490

Affected Products

Laquis Scada