[0day-rubbish] LCDS Laquis SCADA Unauthenticated /uploade.html file write chained with CMDEXT*.DLL autoload (9.8)
Unauthenticated file upload in LCDS Laquis SCADA chains with DLL autoload for code execution, CVSS 9.8.
The 0day Rubbish Research Team disclosed a flaw in LCDS Laquis SCADA that chains an unauthenticated file write at /uploade.html with autoloading of CMDEXT*.DLL files. Successful use runs arbitrary native code in the SCADA web and HMI process, which also hosts the Modbus TCP listener. The issue is CWE-434, scored CVSS 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), and the default configuration has no password. The posting says a full technical analysis is included; it does not report confirmed in-the-wild exploitation.
72