peter bassill · operator
$ cve CVE-2017-6020 JSON

CVE-2017-6020 EXPLOIT

5.3
MEDIUM · CVSS 3.0 · EPSS 8.5% (pctl 95)

Patch early

A public exploit exists.

Description

Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237 do not neutralize external input to ensure that users are not calling for absolute path sequences outside of their privilege level.

Scoring

CVSS5.3 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS8.46% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2018-04-17
Last modified2026-06-17

Affected (1)

VendorProduct
lcdslaquis scada

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD