Vulnerability Details CVE-2018-18990
LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of the web server process.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.395
EPSS Ranking 98.4%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2018-18990
-
cpe:2.3:a:lcds:laquis_scada:4.1
-
cpe:2.3:a:lcds:laquis_scada:4.1.0.3391
-
cpe:2.3:a:lcds:laquis_scada:4.1.0.3870