LAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote code execution.
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
http://laquisscada.com/instale1.php | product vendor advisory |
http://www.securityfocus.com/bid/105719 | third party advisory vdb entry |
https://ics-cert.us-cert.gov/advisories/ICSA-18-289-01 | third party advisory us government resource |
https://exchange.xforce.ibmcloud.com/vulnerabilities/151417 | third party advisory |