Lucene search

K
cveIcscertCVE-2018-18994
HistoryMar 27, 2019 - 6:29 p.m.

CVE-2018-18994

2019-03-2718:29:00
CWE-125
icscert
web.nvd.nist.gov
31
cve-2018-18994
lcds laquis scada
out of bounds read
system crash
data exfiltration

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:P/I:N/A:C

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

36.5%

LCDS Laquis SCADA prior to version 4.1.0.4150 allows an out of bounds read when opening a specially crafted project file, which may cause a system crash or allow data exfiltration.

Affected configurations

Nvd
Node
laquisscadalaquis_scadaRange<4.1.0.4150
VendorProductVersionCPE
laquisscadalaquis_scada*cpe:2.3:a:laquisscada:laquis_scada:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "LCDS Laquis SCADA",
    "vendor": "LCDS Laquis",
    "versions": [
      {
        "status": "affected",
        "version": "All versions prior to version 4.1.0.4150"
      }
    ]
  }
]

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:P/I:N/A:C

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

36.5%

Related for CVE-2018-18994