← Vulnerability feed

Vulnerability record · CVE-2017-6020 · published 17 April 2018

CVE-2017-6020: Lcds laquis scada path traversal vulnerability

Lcds · Laquis Scada

Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237 do not neutralize external input to ensure that users are not calling for absolute path sequences outside of their privilege level.

5.3 CVSS 3.0 Medium EPSS 8.5% · top 5.2% CWE-22 · Path traversal
5.3CVSS 3.0 base score, v2 4.0
8.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237 do not neutralize external input to ensure that users are not calling for absolute path sequences outside of their privilege level.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/97055 Third Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-17-082-01 Third Party AdvisoryUS Government Resource
https://www.exploit-db.com/exploits/42885/ Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/97055 Third Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-17-082-01 Third Party AdvisoryUS Government Resource
https://www.exploit-db.com/exploits/42885/ Third Party AdvisoryVDB Entry

Track CVE-2017-6020 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-18996Lcds laquis scada injection vulnerabilityLCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to …EPSS 2.5%9.8CVE-2018-18998Lcds laquis scada hard-coded credentials vulnerabilityLCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system with high pr…EPSS 2.4%9.8CVE-2018-17893Lcds laquis scada null pointer dereference vulnerabilityLAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote code execution.EPSS 6.4%9.8CVE-2018-17895Lcds laquis scada out-of-bounds read vulnerabilityLAquis SCADA Versions 4.1.0.3870 and prior has several out-of-bounds read vulnerabilities, which may allow remote code execution.EPSS 4.8%9.8CVE-2018-17897Lcds laquis scada integer overflow vulnerabilityLAquis SCADA Versions 4.1.0.3870 and prior has several integer overflow to buffer overflow vulnerabilities, which may allow remote code execution.EPSS 6.0%8.8CVE-2018-18992Lcds laquis scada injection vulnerabilityLCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute remote co…EPSS 2.0%8.8CVE-2018-18988Lcds laquis scada out-of-bounds read vulnerabilityLCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report format file. This may allow remot…EPSS 2.6%8.8CVE-2018-17899Lcds laquis scada path traversal vulnerabilityLAquis SCADA Versions 4.1.0.3870 and prior has a path traversal vulnerability, which may allow remote code execution.EPSS 8.1%

Source: NIST National Vulnerability Database (record CVE-2017-6020), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.