Remote Code Execution Vulnerability in LCDS Laquis SCADA by LDC Systems
CVE-2018-18988

8.8HIGH

Key Information:

Vendor

Ics-cert

Vendor
CVE Published:
1 February 2019

What is CVE-2018-18988?

Prior to version 4.1.0.4150, the LCDS Laquis SCADA system is susceptible to a remote code execution vulnerability due to improper handling of specially crafted report format files. Attackers can exploit this flaw to execute arbitrary script code, potentially leading to scenarios such as data exfiltration and system crashes, posing significant risks to operational integrity and security.

Affected Version(s)

LCDS Laquis SCADA All versions prior to version 4.1.0.4150

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.