An Improper Input Validation vulnerability exists in Trihedral VTScada version 12.0.38 and prior. A specifically malformed HTTP request could cause the affected VTScada to crash. Both local area network (LAN)-only and internet facing systems are affected.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HTrihedral Vtscada
APPTrihedral≤ 12.0.38
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2016-4532CRITICAL9.1PL ✓same product
Path Traversal w interfejsie WAP Trihedral VTScada – odczyt dowolnych plików
CVE-2016-4510CRITICAL9.1PL ✓same product
Auth Bypass w interfejsie WAP Trihedral VTScada — odczyt dowolnych plików
CVE-2016-4523HIGH7.5⚠ KEVsame product
The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers ...
CVE-2017-14029HIGH7.8same product
An Uncontrolled Search Path Element issue was discovered in Trihedral VTScada 11.3.03 and prior. The program w...
CVE-2017-14031HIGH7.8same product
An Improper Access Control issue was discovered in Trihedral VTScada 11.3.03 and prior. A local, non-administr...