CVE Feed

    Dashboard / CVE / CVE-2021-41579

    CVE-2021-41579

    LCDS LAquis SCADA through 4.3.1.1085 is vulnerable to a control bypass and path traversal. If an attacker can get a victim to load a malicious els project file and use the play feature, then the attacker can bypass a consent popup and write arbitrary files to OS locations where the user has permission, leading to code execution.

    Published:Oct 4, 2021
    Last Modified:Nov 21, 2024
    EPS:Oct 4, 2021
    EPSS Score:0.01076
    CVSS Score:7.8

    Affected Products

    Vendor
    Laquisscada
    Product
    Scada

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High