Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-41579

Опубликовано: 04 окт. 2021
Источник: nvd
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

LCDS LAquis SCADA through 4.3.1.1085 is vulnerable to a control bypass and path traversal. If an attacker can get a victim to load a malicious els project file and use the play feature, then the attacker can bypass a consent popup and write arbitrary files to OS locations where the user has permission, leading to code execution.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:laquisscada:scada:*:*:*:*:*:*:*:*
Версия до 4.3.1.1085 (включая)

EPSS

Процентиль: 77%
0.01076
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

github
больше 3 лет назад

LCDS LAquis SCADA through 4.3.1.1085 is vulnerable to a control bypass and path traversal. If an attacker can get a victim to load a malicious els project file and use the play feature, then the attacker can bypass a consent popup and write arbitrary files to OS locations where the user has permission, leading to code execution.

EPSS

Процентиль: 77%
0.01076
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-22