CVE-2018-18998
- EPSS 2.38%
- Veröffentlicht 05.02.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:00
LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system with high privileges.
CVE-2018-18996
- EPSS 2.46%
- Veröffentlicht 05.02.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:00
LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to execute remote code on the server.
CVE-2018-18990
- EPSS 39.49%
- Veröffentlicht 05.02.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:59
LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of the web server process.
CVE-2018-18986
- EPSS 2.67%
- Veröffentlicht 05.02.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:59
LCDS Laquis SCADA prior to version 4.1.0.4150 allows the opening of a specially crafted report format file that may cause an out of bounds read, which may cause a system crash, allow data exfiltration, or remote code execution.
CVE-2018-19004
- EPSS 3.73%
- Veröffentlicht 01.02.2019 18:29:01
- Zuletzt bearbeitet 21.11.2024 03:57:08
LCDS Laquis SCADA prior to version 4.1.0.4150 allows out of bounds read when opening a specially crafted project file, which may allow data exfiltration.
CVE-2018-18988
- EPSS 2.57%
- Veröffentlicht 01.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:59
LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report format file. This may allow remote code execution, data exfiltration, or cause a system crash.
CVE-2018-17911
- EPSS 3.17%
- Veröffentlicht 17.10.2018 02:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:11
LAquis SCADA Versions 4.1.0.3870 and prior has several stack-based buffer overflow vulnerabilities, which may allow remote code execution.
CVE-2018-17901
- EPSS 1.57%
- Veröffentlicht 17.10.2018 02:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:10
LAquis SCADA Versions 4.1.0.3870 and prior, when processing project files the application fails to sanitize user input prior to performing write operations on a stack object, which may allow an attacker to execute code under the current process.
CVE-2018-17899
- EPSS 8.06%
- Veröffentlicht 17.10.2018 02:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:10
LAquis SCADA Versions 4.1.0.3870 and prior has a path traversal vulnerability, which may allow remote code execution.
CVE-2018-17897
- EPSS 5.97%
- Veröffentlicht 17.10.2018 02:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:09
LAquis SCADA Versions 4.1.0.3870 and prior has several integer overflow to buffer overflow vulnerabilities, which may allow remote code execution.