HTTP: LAquis SCADA Web Server Directory Traversal

This signature detects attempts to exploit a known vulnerability against LAquis SCADA. A successful attack can lead to Information Disclosure.

Extended Description

LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of the web server process.

Affected Products

Lcds laquis_scada

References

BugTraq: 106634

CVE: CVE-2018-18990

Short Name
HTTP:DIR:CVE-2018-18990-DIR-TRA
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2018-18990 Directory LAquis SCADA Server Traversal Web bid:106634
Release Date
06/03/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Lcds

CVSS Score

5.0

Found a potential security threat?