Lcds maintains a narrowly focused product line centered on the Laquis SCADA platform, a critical-infrastructure control system that, despite limited product diversity, operates in high-consequence environments where vulnerabilities carry substantial operational risk. The vendor's vulnerability footprint skews toward serious outcomes, with a meaningful share reaching critical severity, reflecting the memory-safety and access-control demands of real-time industrial control software. The exposure recurs through weakness classes including out-of-bounds reads and writes, path-traversal flaws, input-validation gaps, and injection issues—attack vectors that are characteristic of legacy and embedded SCADA codebases where defensive input handling is often secondary to performance and real-time constraints. Defenders operating Laquis deployments should treat this vendor's advisories as urgent and conduct thorough patch validation before deployment, given the unforgiving nature of SCADA environments; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lcds over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18990MEDIUM LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sen | Feb 5, 2019 | 5.3 | 36 | NO | NO |
CVE-2018-17893CRITICAL LAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote code execution. | Oct 17, 2018 | 9.8 | 32 | NO | NO |
CVE-2018-18998CRITICAL LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system with high privileges. | Feb 5, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-18996CRITICAL LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to execute remote code on the serv | Feb 5, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-17897CRITICAL LAquis SCADA Versions 4.1.0.3870 and prior has several integer overflow to buffer overflow vulnerabilities, which may allow remote code execution. | Oct 17, 2018 | 9.8 | 31 | NO | NO |
CVE-2017-6020MEDIUM Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237 do not neutralize external input to ensure that users are n | Apr 17, 2018 | 5.3 | 31 | NO | YES |
CVE-2018-17899HIGH LAquis SCADA Versions 4.1.0.3870 and prior has a path traversal vulnerability, which may allow remote code execution. | Oct 17, 2018 | 8.8 | 30 | NO | NO |
CVE-2018-17895CRITICAL LAquis SCADA Versions 4.1.0.3870 and prior has several out-of-bounds read vulnerabilities, which may allow remote code execution. | Oct 17, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-18988HIGH LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report format file. This may allow remote code execution, data exfiltra | Feb 1, 2019 | 8.8 | 28 | NO | NO |
CVE-2018-18992HIGH LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute remote code on the server. | Feb 5, 2019 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lcds.
Media articles that mention a CVE ID that affects a product developed by Lcds — matched by CVE ID, not by vendor name.