[0day-rubbish] LCDS Laquis SCADA Unauthenticated /uploade.html file write chained with CMDEXT*.DLL autoload (9.8)
Unauthenticated file upload in LCDS Laquis SCADA chains with DLL autoload for code execution, CVSS 9.8.
The 0day Rubbish Research Team disclosed a flaw in LCDS Laquis SCADA that chains an unauthenticated file write at /uploade.html with autoloading of CMDEXT*.DLL files. Successful use runs arbitrary native code in the SCADA web and HMI process, which also hosts the Modbus TCP listener. The issue is CWE-434, scored CVSS 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), and the default configuration has no password. The posting says a full technical analysis is included; it does not report confirmed in-the-wild exploitation.
- Unauthenticated file write is possible through /uploade.html.
- Default installations have no password configured.
- Uploaded CMDEXT DLLs are autoloaded for native code execution.
- CVSS 9.8 and CWE-434; the process also serves Modbus TCP.
Posted by disclosure via Fulldisclosure on Sep 22 0day Rubbish Research Team is publicly disclosing a vulnerability in LCDS Laquis SCADA. Type: Unauthenticated /uploade.html file write chained with CMDEXT*.DLL autoload (CWE-434) CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) Impact: arbitrary native code execution inside the SCADA web and HMI process, which also hosts the Modbus TCP listener Authentication: unauthenticated (no password configured is the default) Full technical analysis and a...
This source does not provide full text. Read it at seclists.org.