Junglewise Threat Intelligence

CVE-2016-4523: Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability

CVE-2016-4523 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-04-15

Executive brief

The WAP interface in Trihedral VTScada allows remote attackers to cause a denial of service via an out-of-bounds read that leads to an application crash. The vulnerability affects versions 8.x through 11.x prior to 11.2.02.

Affected products

  • Trihedral VTScada 8.x through 11.x before 11.2.02

Timeline

  • 2016-06-07: disclosed: Initial advisory ICSA-16-159-01 published by ICS-CERT
  • 2022-04-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog