Vulnerability Intelligence Report
CVE-2016-4532
Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to read arbitrary files via a crafted pathname.
No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
EPSS Probability:27.62%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| trihedral | vtscada | 10.1.05, 10.1.06, 10.1.07, 10.1.12, 9.0.02, 9.0.03, 9.0.08, 9.1.02, 9.1.03, 9.1.05, 9.1.09, 9.1.11, 9.1.14, 9.1.20, 11.0.05, 11.0.07, 10.2.05, 10.2.07, 10.2.08, 10.2.11, 10.2.13, 10.2.14, 10.2.15, 10.2.17, 10.2.19, 10.2.20, 10.2.21, 10.2.22, 8.0.05, 8.0.12, 8.0.16, 8.0.18, 8.1.05, 8.1.06, 11.1.05, 11.1.06, 11.1.09, 11.1.10, 11.1.13, 11.1.14, 11.1.15, 11.1.16, 11.1.17, 11.1.18, 11.1.19, 11.1.20, 11.1.21, 11.1.22, 11.1.24, 10.0.11, 10.0.13, 10.0.14, 10.0.16, 10.0.17 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
27.622%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) · CERT · USA |
| Reserved | 2016-05-05T00:00:00 |
| Published | 2016-06-09T10:00:00 |
| Patch Date | 2016-06-07 |
| Last Updated | 2024-08-06T00:32:25 |
Community Chatter & Buzz