Remote Code Execution Vulnerability in LCDS Laquis SCADA Software
CVE-2018-18992

8.8HIGH

Key Information:

Vendor

Ics-cert

Vendor
CVE Published:
5 February 2019

What is CVE-2018-18992?

The LCDS Laquis SCADA software prior to version 4.1.0.4150 is vulnerable to improper input validation. This security flaw allows an attacker to submit specially crafted user input that may lead to the execution of arbitrary code on the server. Without proper sanitation mechanisms in place, malicious actors can exploit this vulnerability to potentially compromise the integrity and confidentiality of the system.

Affected Version(s)

LCDS Laquis SCADA All versions prior to version 4.1.0.4150

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.