Lcds
Lcds Laquis Scada: vulnerabilidades y CVE
Lcds Laquis Scada tiene 23 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-5040 | Alta (8.5) | 0.41% | — | 21 may 2024 | There are multiple ways in LCDS LAquis SCADA for an attacker to access locations outside of their own directory. |
| CVE-2021-32989 | Media (6.1) | 2.5% | — | 25 may 2022 | When a non-existent resource is requested, the LCDS LAquis SCADA application (version 4.3.1.1011 and prior) returns error messages which may allow reflected cross-site scripting. |
| CVE-2020-10622 | Alta (7.8) | 0.81% | — | 4 may 2020 | LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorized users |
| CVE-2020-10618 | Media (5.5) | 0.83% | — | 4 may 2020 | LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to sensitive information exposure by unauthorized users. |
| CVE-2019-6536 | Alta (7.8) | 1.2% | — | 27 mar 2019 | Opening a specially crafted LCDS LAquis SCADA before 4.3.1.71 ELS file may result in a write past the end of an allocated buffer, which may allow an attacker to execute remote code in the context of the current process. |
| CVE-2018-19029 | Alta (7.8) | 2.7% | — | 5 feb 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows an attacker using a specially crafted project file to supply a pointer for a controlled memory address, which may allow remote code execution, data exfiltration, or… |
| CVE-2018-19002 | Alta (7.8) | 2.7% | — | 5 feb 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially crafted project file, which may allow remote code execution, data exfiltration, or cause a system… |
| CVE-2018-19000 | Media (5.3) | 8.8% | — | 5 feb 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data. |
| CVE-2018-18998 | Crítica (9.8) | 2.4% | — | 5 feb 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system with high privileges. |
| CVE-2018-18996 | Crítica (9.8) | 2.5% | — | 5 feb 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to execute remote code on the server. |
| CVE-2018-18992 | Alta (8.8) | 2.0% | — | 5 feb 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute remote code on the server. |
| CVE-2018-18990 | Media (5.3) | 39% | — | 5 feb 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of… |
| CVE-2018-18986 | Alta (7.8) | 2.7% | — | 5 feb 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows the opening of a specially crafted report format file that may cause an out of bounds read, which may cause a system crash, allow data exfiltration, or remote code… |
| CVE-2018-19004 | Baja (3.3) | 3.7% | — | 1 feb 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows out of bounds read when opening a specially crafted project file, which may allow data exfiltration. |
| CVE-2018-18988 | Alta (8.8) | 2.6% | — | 1 feb 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report format file. This may allow remote code execution, data exfiltration, or cause a system crash. |
| CVE-2018-17911 | Alta (7.8) | 3.2% | — | 17 oct 2018 | LAquis SCADA Versions 4.1.0.3870 and prior has several stack-based buffer overflow vulnerabilities, which may allow remote code execution. |
| CVE-2018-17901 | Alta (7.8) | 1.6% | — | 17 oct 2018 | LAquis SCADA Versions 4.1.0.3870 and prior, when processing project files the application fails to sanitize user input prior to performing write operations on a stack object, which may allow an attacker to execute code… |
| CVE-2018-17899 | Alta (8.8) | 8.1% | — | 17 oct 2018 | LAquis SCADA Versions 4.1.0.3870 and prior has a path traversal vulnerability, which may allow remote code execution. |
| CVE-2018-17897 | Crítica (9.8) | 6.0% | — | 17 oct 2018 | LAquis SCADA Versions 4.1.0.3870 and prior has several integer overflow to buffer overflow vulnerabilities, which may allow remote code execution. |
| CVE-2018-17895 | Crítica (9.8) | 4.8% | — | 17 oct 2018 | LAquis SCADA Versions 4.1.0.3870 and prior has several out-of-bounds read vulnerabilities, which may allow remote code execution. |
| CVE-2018-17893 | Crítica (9.8) | 6.4% | — | 17 oct 2018 | LAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote code execution. |
| CVE-2017-6020 | Media (5.3) | 8.5% | — | 17 abr 2018 | Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237 do not neutralize external input to ensure that users are not calling for absolute path sequences… |
| CVE-2018-5463 | Alta (7.8) | 0.42% | — | 9 abr 2018 | A structured exception handler overflow vulnerability in Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA 4.1.0.3391 and earlier may allow code execution. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.