VendorsTrihedralvtscadaany version
Vulnerabilities

Trihedral VTScada any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2017-14029
An Uncontrolled Search Path Element issue was discovered in Trihedral VTScada 11.3.03 and prior. The program will execute specially crafted malicious dll files placed on the target machine.
Published 2017-11-06 · Modified
9.3EPSS 0.009
CVE-2014-9192
Trihedral Engineering Limited VTScada Integer Overflow
Published 2014-12-11 · Modified
7.8EPSS 0.029
CVE-2017-6043
A Resource Consumption issue was discovered in Trihedral VTScada Versions prior to 11.2.26. The client does not properly validate the input or limit the amount of resources that are utilized by an attacker, which can be used to consume more resources than are available.
Published 2017-06-21 · Modified
7.8EPSS 0.017
CVE-2017-14031
An Improper Access Control issue was discovered in Trihedral VTScada 11.3.03 and prior. A local, non-administrator user has privileges to read and write to the file system of the target machine.
Published 2017-11-06 · Modified
7.8EPSS 0.003
CVE-2016-4523
The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via unspecified vectors.
Published 2016-06-09 · Analyzed
7.5KEVEPSS 0.312
CVE-2017-6045
An Information Exposure issue was discovered in Trihedral VTScada Versions prior to 11.2.26. Some files are exposed within the web server application to unauthenticated users. These files may contain sensitive configuration information.
Published 2017-06-21 · Modified
7.5EPSS 0.017
CVE-2022-3181
An Improper Input Validation vulnerability exists in Trihedral VTScada version 12.0.38 and prior. A specifically malformed HTTP request could cause the affected VTScada to crash. Both local area network (LAN)-only and internet facing systems are affected.
Published 2022-11-02 · Modified
7.5EPSS 0.007
CVE-2017-6053
A Cross-Site Scripting issue was discovered in Trihedral VTScada Versions prior to 11.2.26. A cross-site scripting vulnerability may allow JavaScript code supplied by the attacker to execute within the user's browser.
Published 2017-06-21 · Modified
6.1EPSS 0.008