- EPSS 0.2%
- Veröffentlicht 17.10.2024 16:15:04
- Zuletzt bearbeitet 18.10.2024 12:52:33
In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code into a web page. This could allow an attacker to steal cookies, redirect users, or perform unauthorized actions.
CVE-2024-5040
- EPSS 0.15%
- Veröffentlicht 21.05.2024 21:15:08
- Zuletzt bearbeitet 21.11.2024 09:46:50
There are multiple ways in LCDS LAquis SCADA for an attacker to access locations outside of their own directory.
CVE-2021-32989
- EPSS 0.21%
- Veröffentlicht 25.05.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:08:04
When a non-existent resource is requested, the LCDS LAquis SCADA application (version 4.3.1.1011 and prior) returns error messages which may allow reflected cross-site scripting.
CVE-2020-10622
- EPSS 0.16%
- Veröffentlicht 04.05.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:43
LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorized users
CVE-2020-10618
- EPSS 0.17%
- Veröffentlicht 04.05.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:42
LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to sensitive information exposure by unauthorized users.
CVE-2019-6536
- EPSS 0.16%
- Veröffentlicht 27.03.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:38
Opening a specially crafted LCDS LAquis SCADA before 4.3.1.71 ELS file may result in a write past the end of an allocated buffer, which may allow an attacker to execute remote code in the context of the current process.
CVE-2018-18992
- EPSS 0.44%
- Veröffentlicht 05.02.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:00
LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute remote code on the server.
CVE-2018-19029
- EPSS 0.47%
- Veröffentlicht 05.02.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:11
LCDS Laquis SCADA prior to version 4.1.0.4150 allows an attacker using a specially crafted project file to supply a pointer for a controlled memory address, which may allow remote code execution, data exfiltration, or cause a system crash.
CVE-2018-19002
- EPSS 0.47%
- Veröffentlicht 05.02.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:08
LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially crafted project file, which may allow remote code execution, data exfiltration, or cause a system crash.
CVE-2018-19000
- EPSS 0.45%
- Veröffentlicht 05.02.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:08
LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data.