An Information Exposure issue was discovered in Trihedral VTScada Versions prior to 11.2.26. Some files are exposed within the web server application to unauthenticated users. These files may contain sensitive configuration information.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NTrihedral Vtscada
APPTrihedral≤ 11.2.23
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2016-4510CRITICAL9.1PL ✓same product
Auth Bypass w interfejsie WAP Trihedral VTScada — odczyt dowolnych plików
CVE-2016-4532CRITICAL9.1PL ✓same product
Path Traversal w interfejsie WAP Trihedral VTScada – odczyt dowolnych plików
CVE-2016-4523HIGH7.5⚠ KEVsame product
The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers ...
CVE-2022-3181HIGH7.5same product
An Improper Input Validation vulnerability exists in Trihedral VTScada version 12.0.38 and prior. A specifical...
CVE-2017-14029HIGH7.8same product
An Uncontrolled Search Path Element issue was discovered in Trihedral VTScada 11.3.03 and prior. The program w...