CVE-2016-4523

KEV
Published: Giu 09, 2016 Last Modified: Ott 22, 2025
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,5
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
MEDIUM 5,0
Access Vector: network
Access Complexity: low
Authentication: none
Confidentiality: none
Integrity: none
Availability: partial

Description

AI Translation Available

The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via unspecified vectors.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,6695
Percentile
1,0th
Updated

EPSS Score Trend (Last 91 Days)

125

Out-of-bounds Read

Draft
Common Consequences
Security Scopes Affected:
Confidentiality Availability Other
Potential Impacts:
Read Memory Bypass Protection Mechanism Dos: Crash, Exit, Or Restart Varies By Context
Applicable Platforms
Languages: C, C++, Memory-Unsafe
Technologies: ICS/OT
View CWE Details
Application

Vtscada by Trihedral

Version Range Affected
From 8.0.05 (inclusive)
To 11.2.02 (exclusive)
cpe:2.3:a:trihedral:vtscada:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016…
https://ics-cert.us-cert.gov/advisories/ICSA-16-159-01
http://www.securityfocus.com/bid/91077
http://www.zerodayinitiative.com/advisories/ZDI-16-405
https://ics-cert.us-cert.gov/advisories/ICSA-16-159-01
http://www.securityfocus.com/bid/91077
http://www.zerodayinitiative.com/advisories/ZDI-16-405