RULE(RULE ID:330163)

Rule General Information
Release Date: 2020-05-25
Rule Name: LAquis SCADA NOME HTTP Parameter Command Injection Vulnerability (CVE-2018-18996)
Severity:
CVE ID:
Rule Protection Details
Description: LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to execute remote code on the server.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Others
Reference: SecurityFocusBID:106634
https://ics-cert.us-cert.gov/advisories/ICSA-19-015-01
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://laquisscada.com/