Записи LCDS
23 опубликованных записей вендора lcds.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-787 Out-of-bounds Write3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-125 Out-of-bounds Read3
- CWE-822 Untrusted Pointer Dereference2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-288 Authentication Bypass Using an Alternate Path or Channel1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
23 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2018-17893Эксплойта нет | LAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote code execution.lcds · laquis scada · CWE-822 | Критическая9,8 | — | 6,4 % | 16 окт. 2018 г. |
41В плане | CVE-2018-17897Эксплойта нет | LAquis SCADA Versions 4.1.0.3870 and prior has several integer overflow to buffer overflow vulnerabilities, which may allow remote code execlcds · laquis scada · CWE-190 | Критическая9,8 | — | 6,0 % | 16 окт. 2018 г. |
40В плане | CVE-2018-17895Эксплойта нет | LAquis SCADA Versions 4.1.0.3870 and prior has several out-of-bounds read vulnerabilities, which may allow remote code execution.lcds · laquis scada · CWE-125 | Критическая9,8 | — | 4,8 % | 16 окт. 2018 г. |
40В плане | CVE-2018-18996Эксплойта нет | LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attlcds · laquis scada · CWE-74 | Критическая9,8 | — | 2,5 % | 5 февр. 2019 г. |
40В плане | CVE-2018-18998Эксплойта нет | LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system witlcds · laquis scada · CWE-798 | Критическая9,8 | — | 2,4 % | 5 февр. 2019 г. |
37Наблюдать | CVE-2018-17899Эксплойта нет | LAquis SCADA Versions 4.1.0.3870 and prior has a path traversal vulnerability, which may allow remote code execution.lcds · laquis scada · CWE-22 | Высокая8,8 | — | 8,1 % | 16 окт. 2018 г. |
36Наблюдать | CVE-2018-18988Эксплойта нет | LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report format file.lcds · laquis scada · CWE-125 | Высокая8,8 | — | 2,6 % | 1 февр. 2019 г. |
36Наблюдать | CVE-2018-18992Эксплойта нет | LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute lcds · laquis scada · CWE-74 | Высокая8,8 | — | 2,0 % | 5 февр. 2019 г. |
34Наблюдать | CVE-2024-5040Эксплойта нет | LCDS LAquis SCADA Path Traversallcds · laquis scada · CWE-22 | Высокая8,5 | — | 0,4 % | 21 мая 2024 г. |
33Наблюдать | CVE-2018-18990Эксплойта нет | LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation.lcds · laquis scada · CWE-23 | Средняя5,3 | — | 39,5 % | 5 февр. 2019 г. |
32Наблюдать | CVE-2018-17911Эксплойта нет | LAquis SCADA Versions 4.1.0.3870 and prior has several stack-based buffer overflow vulnerabilities, which may allow remote code execution.lcds · laquis scada · CWE-121 | Высокая7,8 | — | 3,2 % | 16 окт. 2018 г. |
32Наблюдать | CVE-2018-19029Эксплойта нет | LCDS Laquis SCADA prior to version 4.1.0.4150 allows an attacker using a specially crafted project file to supply a pointer for a controlledlcds · laquis scada · CWE-822 | Высокая7,8 | — | 2,7 % | 5 февр. 2019 г. |
32Наблюдать | CVE-2018-18986Эксплойта нет | LCDS Laquis SCADA prior to version 4.1.0.4150 allows the opening of a specially crafted report format file that may cause an out of bounds rlcds · laquis scada · CWE-787 | Высокая7,8 | — | 2,7 % | 5 февр. 2019 г. |
32Наблюдать | CVE-2018-19002Эксплойта нет | LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially crafted project file, wlcds · laquis scada · CWE-94 | Высокая7,8 | — | 2,7 % | 5 февр. 2019 г. |
31Наблюдать | CVE-2018-17901Эксплойта нет | LAquis SCADA Versions 4.1.0.3870 and prior, when processing project files the application fails to sanitize user input prior to performing wlcds · laquis scada · CWE-787 | Высокая7,8 | — | 1,6 % | 16 окт. 2018 г. |
31Наблюдать | CVE-2019-6536Эксплойта нет | Opening a specially crafted LCDS LAquis SCADA before 4.3.1.71 ELS file may result in a write past the end of an allocated buffer, which may lcds · laquis scada · CWE-787 | Высокая7,8 | — | 1,2 % | 27 мар. 2019 г. |
31Наблюдать | CVE-2020-10622Эксплойта нет | LCDS LAquis SCADA Versions 4.3.1 and prior.lcds · laquis scada · CWE-20 | Высокая7,8 | — | 0,8 % | 4 мая 2020 г. |
31Наблюдать | CVE-2018-5463Эксплойта нет | A structured exception handler overflow vulnerability in Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA 4.1.0.33lcds · laquis scada · CWE-703 | Высокая7,8 | — | 0,4 % | 9 апр. 2018 г. |
25Наблюдать | CVE-2021-32989Эксплойта нет | LCDS LAquis SCADA - Cross-site Scriptinglcds · laquis scada · CWE-79 | Средняя6,1 | — | 2,5 % | 25 мая 2022 г. |
24Наблюдать | CVE-2018-19000Эксплойта нет | LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data.lcds · laquis scada · CWE-288 | Средняя5,3 | — | 8,8 % | 5 февр. 2019 г. |
24Наблюдать | CVE-2017-6020Proof of concept | Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237 do not neutralize elcds · laquis scada · CWE-22 | Средняя5,3 | — | 8,5 % | 17 апр. 2018 г. |
22Наблюдать | CVE-2020-10618Эксплойта нет | LCDS LAquis SCADA Versions 4.3.1 and prior.lcds · laquis scada · CWE-200 | Средняя5,5 | — | 0,8 % | 4 мая 2020 г. |
14Наблюдать | CVE-2018-19004Эксплойта нет | LCDS Laquis SCADA prior to version 4.1.0.4150 allows out of bounds read when opening a specially crafted project file, which may allow data lcds · laquis scada · CWE-125 | Низкая3,3 | — | 3,7 % | 1 февр. 2019 г. |
- CVE-2018-1789341В плане
LAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %lcds · laquis scada16 окт. 2018 г.
- CVE-2018-1789741В плане
LAquis SCADA Versions 4.1.0.3870 and prior has several integer overflow to buffer overflow vulnerabilities, which may allow remote code exec
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %lcds · laquis scada16 окт. 2018 г.
- CVE-2018-1789540В плане
LAquis SCADA Versions 4.1.0.3870 and prior has several out-of-bounds read vulnerabilities, which may allow remote code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %lcds · laquis scada16 окт. 2018 г.
- CVE-2018-1899640В плане
LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an att
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %lcds · laquis scada5 февр. 2019 г.
- CVE-2018-1899840В плане
LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system wit
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %lcds · laquis scada5 февр. 2019 г.
- CVE-2018-1789937Наблюдать
LAquis SCADA Versions 4.1.0.3870 and prior has a path traversal vulnerability, which may allow remote code execution.
ВысокаяCVSS 8,8Эксплойта нетEPSS 8 %lcds · laquis scada16 окт. 2018 г.
- CVE-2018-1898836Наблюдать
LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report format file.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %lcds · laquis scada1 февр. 2019 г.
- CVE-2018-1899236Наблюдать
LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %lcds · laquis scada5 февр. 2019 г.
- CVE-2024-504034Наблюдать
LCDS LAquis SCADA Path Traversal
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %lcds · laquis scada21 мая 2024 г.
- CVE-2018-1899033Наблюдать
LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation.
СредняяCVSS 5,3Эксплойта нетEPSS 39 %lcds · laquis scada5 февр. 2019 г.
- CVE-2018-1791132Наблюдать
LAquis SCADA Versions 4.1.0.3870 and prior has several stack-based buffer overflow vulnerabilities, which may allow remote code execution.
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %lcds · laquis scada16 окт. 2018 г.
- CVE-2018-1902932Наблюдать
LCDS Laquis SCADA prior to version 4.1.0.4150 allows an attacker using a specially crafted project file to supply a pointer for a controlled
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %lcds · laquis scada5 февр. 2019 г.
- CVE-2018-1898632Наблюдать
LCDS Laquis SCADA prior to version 4.1.0.4150 allows the opening of a specially crafted report format file that may cause an out of bounds r
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %lcds · laquis scada5 февр. 2019 г.
- CVE-2018-1900232Наблюдать
LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially crafted project file, w
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %lcds · laquis scada5 февр. 2019 г.
- CVE-2018-1790131Наблюдать
LAquis SCADA Versions 4.1.0.3870 and prior, when processing project files the application fails to sanitize user input prior to performing w
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %lcds · laquis scada16 окт. 2018 г.
- CVE-2019-653631Наблюдать
Opening a specially crafted LCDS LAquis SCADA before 4.3.1.71 ELS file may result in a write past the end of an allocated buffer, which may
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %lcds · laquis scada27 мар. 2019 г.
- CVE-2020-1062231Наблюдать
LCDS LAquis SCADA Versions 4.3.1 and prior.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %lcds · laquis scada4 мая 2020 г.
- CVE-2018-546331Наблюдать
A structured exception handler overflow vulnerability in Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA 4.1.0.33
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %lcds · laquis scada9 апр. 2018 г.
- CVE-2021-3298925Наблюдать
LCDS LAquis SCADA - Cross-site Scripting
СредняяCVSS 6,1Эксплойта нетEPSS 2 %lcds · laquis scada25 мая 2022 г.
- CVE-2018-1900024Наблюдать
LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data.
СредняяCVSS 5,3Эксплойта нетEPSS 9 %lcds · laquis scada5 февр. 2019 г.
- CVE-2017-602024Наблюдать
Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237 do not neutralize e
СредняяCVSS 5,3Proof of conceptEPSS 8 %lcds · laquis scada17 апр. 2018 г.
- CVE-2020-1061822Наблюдать
LCDS LAquis SCADA Versions 4.3.1 and prior.
СредняяCVSS 5,5Эксплойта нетEPSS 1 %lcds · laquis scada4 мая 2020 г.
- CVE-2018-1900414Наблюдать
LCDS Laquis SCADA prior to version 4.1.0.4150 allows out of bounds read when opening a specially crafted project file, which may allow data
НизкаяCVSS 3,3Эксплойта нетEPSS 4 %lcds · laquis scada1 февр. 2019 г.