Remote Code Execution and Memory Manipulation in LCDS Laquis SCADA (CVE-2021-XXXX)

Remote Code Execution and Memory Manipulation in LCDS Laquis SCADA (CVE-2021-XXXX)

CVE-2018-19029 · HIGH Severity

AV:N/AC:M/AU:N/C:P/I:P/A:C

LCDS Laquis SCADA prior to version 4.1.0.4150 allows an attacker using a specially crafted project file to supply a pointer for a controlled memory address, which may allow remote code execution, data exfiltration, or cause a system crash.

Learn more about our Web Application Penetration Testing UK.