CVE-2017-6020
Summary
| CVE | CVE-2017-6020 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-04-17 14:29:00 UTC |
| Updated | 2019-10-09 23:28:00 UTC |
| Description | Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237 do not neutralize external input to ensure that users are not calling for absolute path sequences outside of their privilege level. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Lcds | Laquis Scada | All | All | All | All |
| Application | Lcds | Laquis Scada | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| LCDS - Leão Consultoria e Desenvolvimento de Sistemas LTDA ME LAquis SCADA | ICS-CERT | MISC | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| 97055 | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| LAquis SCADA 4.1.0.2385 - Directory Traversal (Metasploit) - Multiple remote Exploit | EXPLOIT-DB | www.exploit-db.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.