Skip to content
COOEY

EXPOSURES › CVE-2016-4523

CVE-2016-4523

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-04-15 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-4523 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatched

Trihedral VTScada's WAP interface allows remote attackers to cause a denial-of-service attack.

The WAP interface in Trihedral VTScada (formerly VTS) contains a vulnerability that enables remote denial-of-service attacks. For DIB organizations, this means critical industrial control systems could be taken offline by adversaries, disrupting operations and violating continuity requirements under NIST 800-171. Organizations must ensure their SCADA systems are patched and monitored for exploitation attempts.

Shame score — A known DoS vulnerability in industrial control software that was actively exploited in the KEV catalog, indicating negligent patching and avoidable operational disruption.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS).

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.