CVE-2018-18990
15Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 39%
exploitation probability
39%top 1% of all CVEs
observed exploitation
nono source reports it
LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of the web server process.
Affected products
ICS-CERT · LCDS Laquis SCADA