Trihedral VTScada Integer Overflow Vulnerability
Release date:
Updated on:
Affected Systems:
Trihedral VTScada <11.1.07
Trihedral VTScada <10.2.22
Trihedral VTScada 6.5-9.1.20
Description:
CVE (CAN) ID: CVE-2014-9192
VTScada is a Windows-based SCADA System with Web Interface Options.
Trihedral Engineering VTScada (earlier than VTS) 6.5-9.1.20, 10.2.22, and earlier than 11.1.07 have the integer overflow vulnerability in implementation. Remote attackers trigger a large amount of memory allocation by constructing requests, this vulnerability can cause DoS and server crashes.
<* Source: anonymous
Link: https://ics-cert.us-cert.gov//advisories/ICSA-14-343-02
*>
Suggestion:
Vendor patch:
Trihedral
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.trihedral.com/help/#Op_Welcome/Wel_UpgradeNotes.htm
Https://ics-cert.us-cert.gov/redirect? Url = ftp % 3A % 2F % 2Fftp.trihedral.com % 2 FVTS % 2F
This article permanently updates the link address: