CVE-2017-6016
An Improper Access Control issue was discovered in LCDS - Leao Consultoria e Desenvolvimento de Sistemas LTDA ME LAquis SCADA.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An Improper Access Control issue was discovered in LCDS - Leao Consultoria e Desenvolvimento de Sistemas LTDA ME LAquis SCADA. The following versions are affected: Versions 4.1 and prior versions released before January 20, 2017. An Improper Access Control vulnerability has been identified, which may allow an authenticated user to modify application files to escalate privileges.
- CVSS 3.0
- 7.3 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- leao consultoria e desenvolvimento de sistemas/ltda me laquis scada
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/96942Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-075-01Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/96942Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-075-01Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.