Vulnerabilities
9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-3181 | An Improper Input Validation vulnerability exists in Trihedral VTScada version 12.0.38 and prior. An Improper Input Validation vulnerability exists in Trihedral VTScada version 12.0.38 and prior. A specifically malformed HTTP request could cause the affected VTScada to crash. Both local area network (LAN)-only and internet facing systems are affected. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2017-14029 +1 in the same advisory: …14031 | An Uncontrolled Search Path Element issue was discovered in Trihedral VTScada 11.3.03 and prior. An Uncontrolled Search Path Element issue was discovered in Trihedral VTScada 11.3.03 and prior. The program will execute specially crafted malicious dll files placed on the target machine. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2017-6043 | A Resource Consumption issue was discovered in Trihedral VTScada Versions prior to 11.2.26. A Resource Consumption issue was discovered in Trihedral VTScada Versions prior to 11.2.26. The client does not properly validate the input or limit the amount of resources that are utilized by an attacker, which can be used to consume more resources than are available. NVD description · AI analysis pending | 7.5 group max | 2% |
| — | ||
| CVE-2016-4532 +1 in the same advisory: …4510 | Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to read arbit Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to read arbitrary files via a crafted pathname. NVD description · AI analysis pending | 9.1 | 28% |
| — | ||
| CVE-2016-4523 | Remote Denial-of-Service in Trihedral VTScada WAP Interface CVE-2016-4523 is a remotely exploitable denial-of-service vulnerability in the WAP interface of Trihedral VTScada (formerly VTS), classified under CWE-119 (improper memory-bounds handling). A remote attacker can crash the VTScada service by sending crafted requests to the WAP interface, disrupting the SCADA/HMI application until the process is restarted; there is no indication of code execution. Organizations running VTScada/VTS where the WAP interface is reachable from untrusted or internet-facing networks are affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-04-15, confirming exploitation in the wild years after publication (ransomware use: unknown), and the high EPSS score (30.7% within 30 days, 98th percentile) suggests meaningful near-term exploitation risk even though no public PoC is known. Do: Apply updates from Trihedral per vendor instructions, as required by the CISA KEV catalog entry. As an interim mitigation, restrict the WAP interface to trusted networks (firewall or ACL it away from internet-facing access) and check whether your deployment exposes WAP services externally. Monitor for repeated crashes of the VTScada service, which would indicate active exploitation attempts. | 7.5 | 31% | KEV |
| nicheunknown (no published install-base or internet-exposure counts) |