Show filters
27 Total Results
Displaying 1-10 of 27
Sort by:
Attacker Value
Unknown
CVE-2024-9414
Disclosure Date: October 17, 2024 (last updated October 18, 2024)
In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code into a web page. This could allow an attacker to steal cookies, redirect users, or perform unauthorized actions.
0
Attacker Value
Unknown
CVE-2024-5040
Disclosure Date: May 21, 2024 (last updated May 22, 2024)
There are multiple ways in
LCDS LAquis SCADA for an attacker to access locations outside of their own directory.
0
Attacker Value
Unknown
CVE-2021-32989
Disclosure Date: May 25, 2022 (last updated October 07, 2023)
When a non-existent resource is requested, the LCDS LAquis SCADA application (version 4.3.1.1011 and prior) returns error messages which may allow reflected cross-site scripting.
0
Attacker Value
Unknown
CVE-2020-10618
Disclosure Date: May 04, 2020 (last updated February 21, 2025)
LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to sensitive information exposure by unauthorized users.
0
Attacker Value
Unknown
CVE-2020-10622
Disclosure Date: May 04, 2020 (last updated February 21, 2025)
LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorized users
0
Attacker Value
Unknown
CVE-2018-18994
Disclosure Date: March 27, 2019 (last updated November 27, 2024)
LCDS Laquis SCADA prior to version 4.1.0.4150 allows an out of bounds read when opening a specially crafted project file, which may cause a system crash or allow data exfiltration.
0
Attacker Value
Unknown
CVE-2019-6536
Disclosure Date: March 27, 2019 (last updated November 27, 2024)
Opening a specially crafted LCDS LAquis SCADA before 4.3.1.71 ELS file may result in a write past the end of an allocated buffer, which may allow an attacker to execute remote code in the context of the current process.
0
Attacker Value
Unknown
CVE-2018-18990
Disclosure Date: February 05, 2019 (last updated November 27, 2024)
LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of the web server process.
0
Attacker Value
Unknown
CVE-2018-19000
Disclosure Date: February 05, 2019 (last updated November 27, 2024)
LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data.
0
Attacker Value
Unknown
CVE-2018-19029
Disclosure Date: February 05, 2019 (last updated November 27, 2024)
LCDS Laquis SCADA prior to version 4.1.0.4150 allows an attacker using a specially crafted project file to supply a pointer for a controlled memory address, which may allow remote code execution, data exfiltration, or cause a system crash.
0