CVE-2018-17893
9.8
CRITICAL · CVSS 3.0 · EPSS 6.4% (pctl 93)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
LAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote code execution.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.38% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-822 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-10-17 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| lcds | laquis scada |
References
- http://laquisscada.com/instale1.php
- http://www.securityfocus.com/bid/105719
- https://ics-cert.us-cert.gov/advisories/ICSA-18-289-01
- https://exchange.xforce.ibmcloud.com/vulnerabilities/151417
- http://laquisscada.com/instale1.php
- http://www.securityfocus.com/bid/105719
- https://ics-cert.us-cert.gov/advisories/ICSA-18-289-01
→ the Explorer · watch your stack · NVD