CVE-2018-18990
LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive informatio...
Description
This CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: central@cisa.dhs.gov
In plain language
AI Low urgencyCVE-2018-18990 is a flaw in LCDS Laquis SCADA that can let an attacker read sensitive files by using a specially crafted file path; for most small businesses it’s a low-to-medium worry, but you should update if you run this SCADA software and can reach its interfaces.
CVE-2018-18990 is a path-handling weakness (CWE-23/CWE-22) in LCDS Laquis SCADA where a user-supplied path is used in file operations before proper validation, potentially enabling information disclosure; it was fixed in version 4.1.0.4150.
What to do now
- Check which version of LCDS Laquis SCADA (laquis scada) you are running in your environment.
- If your version is older than 4.1.0.4150, plan an upgrade.
- Upgrade LCDS Laquis SCADA to 4.1.0.4150 (or later) to close the path-validation issue.
- After upgrading, verify the SCADA file-related functions you use still work as expected and review application logs for unusual file access attempts.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:LConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-18990 and every CVE in our database. Create a free account — no credit card required.
Create Free Account