Vulnerabilities > CVE-2018-19029 - NULL Pointer Dereference vulnerability in Lcds Laquis Scada 4.1/4.1.0.3391/4.1.0.3870

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
lcds
CWE-476

Summary

LCDS Laquis SCADA prior to version 4.1.0.4150 allows an attacker using a specially crafted project file to supply a pointer for a controlled memory address, which may allow remote code execution, data exfiltration, or cause a system crash.

Vulnerable Configurations

Part Description Count
Application
Lcds
3

Common Weakness Enumeration (CWE)