Show filters
27 Total Results
Displaying 1-10 of 27
Sort by:
Attacker Value
Unknown

CVE-2024-9414

Disclosure Date: October 17, 2024 (last updated October 18, 2024)
In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code into a web page. This could allow an attacker to steal cookies, redirect users, or perform unauthorized actions.
0
Attacker Value
Unknown

CVE-2024-5040

Disclosure Date: May 21, 2024 (last updated May 22, 2024)
There are multiple ways in LCDS LAquis SCADA for an attacker to access locations outside of their own directory.
0
Attacker Value
Unknown

CVE-2021-32989

Disclosure Date: May 25, 2022 (last updated October 07, 2023)
When a non-existent resource is requested, the LCDS LAquis SCADA application (version 4.3.1.1011 and prior) returns error messages which may allow reflected cross-site scripting.
Attacker Value
Unknown

CVE-2020-10618

Disclosure Date: May 04, 2020 (last updated February 21, 2025)
LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to sensitive information exposure by unauthorized users.
Attacker Value
Unknown

CVE-2020-10622

Disclosure Date: May 04, 2020 (last updated February 21, 2025)
LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorized users
Attacker Value
Unknown

CVE-2018-18994

Disclosure Date: March 27, 2019 (last updated November 27, 2024)
LCDS Laquis SCADA prior to version 4.1.0.4150 allows an out of bounds read when opening a specially crafted project file, which may cause a system crash or allow data exfiltration.
0
Attacker Value
Unknown

CVE-2019-6536

Disclosure Date: March 27, 2019 (last updated November 27, 2024)
Opening a specially crafted LCDS LAquis SCADA before 4.3.1.71 ELS file may result in a write past the end of an allocated buffer, which may allow an attacker to execute remote code in the context of the current process.
0
Attacker Value
Unknown

CVE-2018-18990

Disclosure Date: February 05, 2019 (last updated November 27, 2024)
LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of the web server process.
0
Attacker Value
Unknown

CVE-2018-19000

Disclosure Date: February 05, 2019 (last updated November 27, 2024)
LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data.
0
Attacker Value
Unknown

CVE-2018-19029

Disclosure Date: February 05, 2019 (last updated November 27, 2024)
LCDS Laquis SCADA prior to version 4.1.0.4150 allows an attacker using a specially crafted project file to supply a pointer for a controlled memory address, which may allow remote code execution, data exfiltration, or cause a system crash.
0