HTTP: LAquis SCADA Web Server relatorionome NOME Command Injection

This signature detects attempts to exploit a known vulnerability against LAquis SCADA Web Server. A successful attack can lead to arbitrary code execution.

Extended Description

LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to execute remote code on the server.

Affected Products

Lcds laquis_scada

References

BugTraq: 106634

CVE: CVE-2018-18996

Short Name
HTTP:MISC:LAQUIS-SCADA-CE
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2018-18996 Command Injection LAquis NOME SCADA Server Web bid:106634 relatorionome
Release Date
03/13/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Lcds

CVSS Score

7.5

Found a potential security threat?