EXPOSURES › CVE-2016-4523
CVE-2016-4523
HIGH ⌖ ON CISA KEV · EXPLOITEDTrihedral VTScada's WAP interface allows remote attackers to cause a denial-of-service attack.
The WAP interface in Trihedral VTScada (formerly VTS) contains a vulnerability that enables remote denial-of-service attacks. For DIB organizations, this means critical industrial control systems could be taken offline by adversaries, disrupting operations and violating continuity requirements under NIST 800-171. Organizations must ensure their SCADA systems are patched and monitored for exploitation attempts.
Shame score — A known DoS vulnerability in industrial control software that was actively exploited in the KEV catalog, indicating negligent patching and avoidable operational disruption.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS).