An Improper Input Validation vulnerability exists in Trihedral VTScada version 12.0.38 and prior. A specifically malformed HTTP request could cause the affected VTScada to crash. Both local area network (LAN)-only and internet facing systems are affected.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HTrihedral Vtscada
APPTrihedral≤ 12.0.38
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2016-4532CRITICAL9.1PL ✓ten sam produkt
Path Traversal w interfejsie WAP Trihedral VTScada – odczyt dowolnych plików
CVE-2016-4510CRITICAL9.1PL ✓ten sam produkt
Auth Bypass w interfejsie WAP Trihedral VTScada — odczyt dowolnych plików
CVE-2016-4523HIGH7.5⚠ KEVten sam produkt
The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers ...
CVE-2017-14029HIGH7.8ten sam produkt
An Uncontrolled Search Path Element issue was discovered in Trihedral VTScada 11.3.03 and prior. The program w...
CVE-2017-14031HIGH7.8ten sam produkt
An Improper Access Control issue was discovered in Trihedral VTScada 11.3.03 and prior. A local, non-administr...