PT-2022-20947 · Trihedral · Vtscada

Trihedral

·

Published

2022-11-02

·

Updated

2022-11-04

·

CVE-2022-3181

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Trihedral VTScada versions prior to 12.0.38
Description An issue exists due to improper input validation, where a specifically malformed HTTP request could cause the affected system to crash. Both local area network (LAN)-only and internet-facing systems are affected.
Recommendations For versions prior to 12.0.38, update to a version newer than 12.0.38 to resolve the issue. As a temporary workaround, consider restricting access to the system to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-3181

Affected Products

Vtscada