Path traversal in LAquis SCADA - CVE-2018-17899

 

Path traversal in LAquis SCADA - CVE-2018-17899

Published: October 17, 2018


Vulnerability identifier: #VU15385
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17899
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to conduct directory traversal on the target system.

The vulnerability exists due to path traversal. A remote unauthenticated attacker can trick the victim into visiting a specially crafted website, conduct directory traversal attack and execute arbitrary code.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

LAquis SCADA

How to mitigate CVE-2018-17899

Update to version 4.1.0.4114.

LAquis SCADA - update to 4.1.0.4114

External References

Related Security Bulletins