ZeroHour

CVE-2016-4523

KEVniche

Remote Denial-of-Service in Trihedral VTScada WAP Interface

CISA: Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability

CVSS 3.1
7.5 high
EPSS
31%p98
Published
()
KEV added
AI analysis

CVE-2016-4523 is a remotely exploitable denial-of-service vulnerability in the WAP interface of Trihedral VTScada (formerly VTS), classified under CWE-119 (improper memory-bounds handling). A remote attacker can crash the VTScada service by sending crafted requests to the WAP interface, disrupting the SCADA/HMI application until the process is restarted; there is no indication of code execution. Organizations running VTScada/VTS where the WAP interface is reachable from untrusted or internet-facing networks are affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-04-15, confirming exploitation in the wild years after publication (ransomware use: unknown), and the high EPSS score (30.7% within 30 days, 98th percentile) suggests meaningful near-term exploitation risk even though no public PoC is known.

What to do: Apply updates from Trihedral per vendor instructions, as required by the CISA KEV catalog entry. As an interim mitigation, restrict the WAP interface to trusted networks (firewall or ACL it away from internet-facing access) and check whether your deployment exposes WAP services externally. Monitor for repeated crashes of the VTScada service, which would indicate active exploitation attempts.

Affected
Trihedral VTScada (formerly VTS)
Estimated exposure
nicheunknown (no published install-base or internet-exposure counts) — No public install-base figures or internet-scan statistics exist for Trihedral VTScada, but it is a niche SCADA/HMI platform deployed mainly at utilities and small-to-midsize industrial sites, so total deployments are plausibly in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via unspecified vectors.

CISA Known Exploited Vulnerability
Affected
Trihedral VTScada (formerly VTS)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
trihedral
Products
vtscada
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news