CVE-2021-41579
HIGHLCDS LAquis SCADA <= 4.3.1.1085 - Path Traversal and Arbitrary File Write via Malicious ELS Project File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-41579. PoCs published by mbanyamer.
AI-analyzed exploit summary This PoC demonstrates an arbitrary file write vulnerability in LCDS LAquis SCADA <= 4.3.1.1085 via path traversal in malicious .els project files. It modifies legitimate .els files to include traversal sequences, allowing file writes to arbitrary locations when the victim opens and plays the project.
Description
LCDS LAquis SCADA through 4.3.1.1085 is vulnerable to a control bypass and path traversal. If an attacker can get a victim to load a malicious els project file and use the play feature, then the attacker can bypass a consent popup and write arbitrary files to OS locations where the user has permission, leading to code execution.
Exploits (1)
This PoC demonstrates an arbitrary file write vulnerability in LCDS LAquis SCADA <= 4.3.1.1085 via path traversal in malicious .els project files. It modifies legitimate .els files to include traversal sequences, allowing file writes to arbitrary locations when the victim opens and plays the project.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H