Lucene search

K
cveIcscertCVE-2018-18992
HistoryFeb 05, 2019 - 6:29 p.m.

CVE-2018-18992

2019-02-0518:29:00
CWE-74
icscert
web.nvd.nist.gov
53
cve-2018-18992
lcds laquis scada
remote code execution
nvd
information security

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.053

Percentile

93.1%

LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute remote code on the server.

Affected configurations

Nvd
Node
lcdslaquis_scadaRange<4.1.0.4150
VendorProductVersionCPE
lcdslaquis_scada*cpe:2.3:a:lcds:laquis_scada:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "LCDS Laquis SCADA",
    "vendor": "ICS-CERT",
    "versions": [
      {
        "status": "affected",
        "version": "All versions prior to version 4.1.0.4150"
      }
    ]
  }
]

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.053

Percentile

93.1%