Back

CVE-2016-4532

CRITICAL

Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to read arbitrary files via a crafted pathname.

Published: Jun 9, 2016 Modified: Jun 17, 2026
CWE-22

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products (54)

Vendor Product Version
trihedral vtscada 10.1.05
trihedral vtscada 10.1.06
trihedral vtscada 10.1.07
trihedral vtscada 10.1.12
trihedral vtscada 9.0.02
trihedral vtscada 9.0.03
trihedral vtscada 9.0.08
trihedral vtscada 9.1.02
trihedral vtscada 9.1.03
trihedral vtscada 9.1.05
trihedral vtscada 9.1.09
trihedral vtscada 9.1.11
trihedral vtscada 9.1.14
trihedral vtscada 9.1.20
trihedral vtscada 11.0.05
trihedral vtscada 11.0.07
trihedral vtscada 10.2.05
trihedral vtscada 10.2.07
trihedral vtscada 10.2.08
trihedral vtscada 10.2.11

…and 34 more

GitHub Security Advisory GHSA-4343-27r5-p3v9

Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x...

Risk Scores

CVSS Score 9.1 / 10
EPSS Score 27.62%

Top 2% most likely to be exploited

Threat Score 44.7 / 100

Data Sources

NVD EPSS GitHub