CVE-2016-4523
KEVnicheRemote Denial-of-Service in Trihedral VTScada WAP Interface
CISA: Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability
CVE-2016-4523 is a remotely exploitable denial-of-service vulnerability in the WAP interface of Trihedral VTScada (formerly VTS), classified under CWE-119 (improper memory-bounds handling). A remote attacker can crash the VTScada service by sending crafted requests to the WAP interface, disrupting the SCADA/HMI application until the process is restarted; there is no indication of code execution. Organizations running VTScada/VTS where the WAP interface is reachable from untrusted or internet-facing networks are affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-04-15, confirming exploitation in the wild years after publication (ransomware use: unknown), and the high EPSS score (30.7% within 30 days, 98th percentile) suggests meaningful near-term exploitation risk even though no public PoC is known.
What to do: Apply updates from Trihedral per vendor instructions, as required by the CISA KEV catalog entry. As an interim mitigation, restrict the WAP interface to trusted networks (firewall or ACL it away from internet-facing access) and check whether your deployment exposes WAP services externally. Monitor for repeated crashes of the VTScada service, which would indicate active exploitation attempts.
| Trihedral VTScada (formerly VTS) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via unspecified vectors.
- Affected
- Trihedral VTScada (formerly VTS)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- trihedral
- Products
- vtscada
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H