jacob-baines/vuln_disclosure

jacob-baines/vuln_disclosure

Releases0
Stars1

CVE History

CVEPublishedCVSS v3CVSS v2
7.8 HIGH6.8 MEDIUM

mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files. If an attacker can trick a victim into importing a malicious mep file, then they gain the ability to write arbitrary files to OS locations where the user has permission. This would typically lead to code execution.

7.8 HIGH6.8 MEDIUM

LCDS LAquis SCADA through 4.3.1.1085 is vulnerable to a control bypass and path traversal. If an attacker can get a victim to load a malicious els project file and use the play feature, then the attacker can bypass a consent popup and write arbitrary files to OS locations where the user has permission, leading to code execution.