Path Traversal Vulnerability in LCDS Laquis SCADA Software by Laquis
CVE-2018-18990

5.3MEDIUM

Key Information:

Vendor

Ics-cert

Vendor
CVE Published:
5 February 2019

What is CVE-2018-18990?

Prior to version 4.1.0.4150, LCDS Laquis SCADA is susceptible to path traversal attacks due to improper validation of user-supplied paths in file operations. This vulnerability may be exploited by attackers to gain unauthorized access to sensitive information on the web server, potentially compromising system security. Proper validation of input paths is essential to mitigate this risk.

Affected Version(s)

LCDS Laquis SCADA All versions prior to version 4.1.0.4150

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.