Back
CVE-2016-4532
CRITICAL
Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to read arbitrary files via a crafted pathname.
Published: Jun 9, 2016
Modified: Jun 17, 2026
CWE-22
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products (54)
| Vendor | Product | Version |
|---|---|---|
| trihedral | vtscada | 10.1.05 |
| trihedral | vtscada | 10.1.06 |
| trihedral | vtscada | 10.1.07 |
| trihedral | vtscada | 10.1.12 |
| trihedral | vtscada | 9.0.02 |
| trihedral | vtscada | 9.0.03 |
| trihedral | vtscada | 9.0.08 |
| trihedral | vtscada | 9.1.02 |
| trihedral | vtscada | 9.1.03 |
| trihedral | vtscada | 9.1.05 |
| trihedral | vtscada | 9.1.09 |
| trihedral | vtscada | 9.1.11 |
| trihedral | vtscada | 9.1.14 |
| trihedral | vtscada | 9.1.20 |
| trihedral | vtscada | 11.0.05 |
| trihedral | vtscada | 11.0.07 |
| trihedral | vtscada | 10.2.05 |
| trihedral | vtscada | 10.2.07 |
| trihedral | vtscada | 10.2.08 |
| trihedral | vtscada | 10.2.11 |
…and 34 more
GitHub Security Advisory GHSA-4343-27r5-p3v9
Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x...
References (6)
- http://www.securityfocus.com/bid/91077
- http://www.zerodayinitiative.com/advisories/ZDI-16-403
- https://ics-cert.us-cert.gov/advisories/ICSA-16-159-01 Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/91077
- http://www.zerodayinitiative.com/advisories/ZDI-16-403
- https://ics-cert.us-cert.gov/advisories/ICSA-16-159-01 Third Party Advisory, US Government Resource
Risk Scores
CVSS Score
9.1 / 10
EPSS Score
27.62%
Top 2% most likely to be exploited
Threat Score
44.7 / 100
Data Sources
NVD
EPSS
GitHub