← back
CVE-2018-18990CWE-23

CVE-2018-18990

15Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 39%
exploitation probability
39%top 1% of all CVEs
observed exploitation
nono source reports it
LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of the web server process.