LCDS Laquis SCADA prior to version 4.1.0.4150 allows an attacker using a specially crafted project file to supply a pointer for a controlled memory address, which may allow remote code execution, data exfiltration, or cause a system crash.
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-19-015-01 | third party advisory us government resource |
http://www.securityfocus.com/bid/106634 | third party advisory vdb entry |