LCDS Laquis SCADA prior to version 4.1.0.4150 allows out of bounds read when opening a specially crafted project file, which may allow data exfiltration.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-19-015-01 | third party advisory us government resource |
http://www.securityfocus.com/bid/106634 | third party advisory vdb entry |