Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lcds

First CVE: Apr 9, 2018Active for: 8 yearsTotal CVEs: 23
63.2
VTI Score
TOP TARGET

Lcds maintains a narrowly focused product line centered on the Laquis SCADA platform, a critical-infrastructure control system that, despite limited product diversity, operates in high-consequence environments where vulnerabilities carry substantial operational risk. The vendor's vulnerability footprint skews toward serious outcomes, with a meaningful share reaching critical severity, reflecting the memory-safety and access-control demands of real-time industrial control software. The exposure recurs through weakness classes including out-of-bounds reads and writes, path-traversal flaws, input-validation gaps, and injection issues—attack vectors that are characteristic of legacy and embedded SCADA codebases where defensive input handling is often secondary to performance and real-time constraints. Defenders operating Laquis deployments should treat this vendor's advisories as urgent and conduct thorough patch validation before deployment, given the unforgiving nature of SCADA environments; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
4.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Lcds over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 9, 2018
8 years ago
Most Recent CVE
May 21, 2024
793 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-18990MEDIUM
LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sen
Feb 5, 20195.336NONO
CVE-2018-17893CRITICAL
LAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote code execution.
Oct 17, 20189.832NONO
CVE-2018-18998CRITICAL
LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system with high privileges.
Feb 5, 20199.831NONO
CVE-2018-18996CRITICAL
LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to execute remote code on the serv
Feb 5, 20199.831NONO
CVE-2018-17897CRITICAL
LAquis SCADA Versions 4.1.0.3870 and prior has several integer overflow to buffer overflow vulnerabilities, which may allow remote code execution.
Oct 17, 20189.831NONO
CVE-2017-6020MEDIUM
Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237 do not neutralize external input to ensure that users are n
Apr 17, 20185.331NOYES
CVE-2018-17899HIGH
LAquis SCADA Versions 4.1.0.3870 and prior has a path traversal vulnerability, which may allow remote code execution.
Oct 17, 20188.830NONO
CVE-2018-17895CRITICAL
LAquis SCADA Versions 4.1.0.3870 and prior has several out-of-bounds read vulnerabilities, which may allow remote code execution.
Oct 17, 20189.830NONO
CVE-2018-18988HIGH
LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report format file. This may allow remote code execution, data exfiltra
Feb 1, 20198.828NONO
CVE-2018-18992HIGH
LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute remote code on the server.
Feb 5, 20198.827NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
22%
52%
22%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local11 (47.8%)
Network12 (52.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (39.1%)
Unknown0 (0.0%)
Required14 (60.9%)
Privileges Required
Low1 (4.3%)
High0 (0.0%)
None22 (95.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lcds.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lcds — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lcds's Products

View all 1 CNAs →

Top CWEs