SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-18990

LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation.

MEDIUM 5.3EPSS 39.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 39.5%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of the web server process.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
39.49% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-23, CWE-22
Affected
lcds/laquis scada
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.