LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2016-4523: Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 15, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 6, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2016-4523 to its Known Exploited Vulnerabilities catalog on Apr 15, 2022, with a federal patch deadline of May 6, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS).

CVE-2016-4523 is a denial-of-service vulnerability in the WAP interface of Trihedral VTScada (formerly VTS). Remote attackers can abuse it to disrupt availability of the affected system. For operators of industrial or SCADA environments that rely on this product, loss of the interface or related services can interrupt monitoring and control functions, so timely identification and remediation matter.

Public detail is limited to the CISA summary and the stated weakness class. Confirm exact impact, affected builds, and fixed releases against the vendor advisory before acting.

How it works

The vulnerability is classified as CWE-119 (improper restriction of operations within the bounds of a memory buffer). In products of this class, flawed handling of input to a network-facing interface can allow an attacker to trigger memory corruption or resource exhaustion that crashes or hangs the service.

According to the CISA summary, the flaw resides in the WAP interface of Trihedral VTScada. A remote attacker who can reach that interface may send crafted traffic that causes a denial-of-service condition. Specifics of packet format, required authentication, or exact crash behavior are not provided in the given facts; treat any public proof-of-concept claims cautiously and validate them only against vendor or trusted researcher documentation. The practical result is loss of availability rather than confirmed remote code execution or data theft from this CVE alone.

Am I affected? How to find it in your systems

Trihedral VTScada is typically deployed in industrial control, SCADA, and HMI environments for process monitoring and automation. It may run on dedicated operator workstations, servers, or embedded systems that expose the WAP interface on the network.

If asset management data is incomplete, prioritize systems that provide critical visibility or control and assume they may be vulnerable until proven otherwise by version check.

How to remediate

The required action is to apply updates per vendor instructions. Obtain the security update or patched release that addresses CVE-2016-4523 directly from Trihedral, verify integrity of the package, and deploy it in accordance with your change-control process.

If the vendor advisory lists additional configuration changes or compensating settings, implement those as well.

If you can't patch immediately

When immediate patching is not feasible, reduce exposure with compensating controls while you schedule the update.

These measures lower risk but do not replace the vendor update. Known ransomware use is not documented for this CVE; still treat any successful DoS as a potential precursor to further intrusion and investigate accordingly.

If your data may have been exposed

Actively exploited vulnerabilities can lead to broader compromise even when the initial flaw is a denial-of-service condition. If you observe exploitation attempts or unexplained outages on affected systems, follow your incident-response plan: isolate affected hosts, preserve logs, and assess whether credentials or adjacent systems were touched. You can run a free exposure scan of your email addresses to check whether they appear in known breach data sets and take additional account-protection steps if they do.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTrihedral · VTScada (formerly VTS)
WeaknessCWE-119
Added to CISA KEVApr 15, 2022
Federal patch deadlineMay 6, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities