Vulnerabilities > CVE-2018-17901 - Out-of-bounds Write vulnerability in Lcds Laquis Scada 4.1/4.1.0.3391/4.1.0.3870

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
lcds
CWE-787

Summary

LAquis SCADA Versions 4.1.0.3870 and prior, when processing project files the application fails to sanitize user input prior to performing write operations on a stack object, which may allow an attacker to execute code under the current process.

Vulnerable Configurations

Part Description Count
Application
Lcds
3

Common Weakness Enumeration (CWE)