QID 590515

Date Published: 2021-09-07

QID 590515: LCDS LAquis SCADA Cross-site Scripting Vulnerability (ICSA-21-208-04)

AFFECTED PRODUCTS
The following versions of LAquis SCADA are affected:
Versions 4.3.1.1011 and prior

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

Successful exploitation of this vulnerability may allow an unauthenticated remote attacker to access sensitive information or execute arbitrary code.

  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-208-04 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590515

    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-208-04 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-208-04