Trianglemicroworks develops supervisory control and data acquisition (SCADA) components and industrial communications libraries, including DNP3 and IEC 60870-5 protocol implementations and gateway products, that operate in critical infrastructure and utility networks. While the vendor's product portfolio is narrow, its libraries and protocol stacks achieve broad deployment as embedded components across industrial control systems and third-party integrations, placing it among the more prominent vendors in critical-infrastructure vulnerability tracking. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes including path traversal, missing authentication, improper input validation, memory-bounds violations, and out-of-bounds writes that reflect both the protocol-parsing complexity and the operational-technology deployment context of SCADA components. Defenders should prioritize inventory and patching of affected SCADA gateways and systems that incorporate this vendor's protocol libraries, as flaws in industrial communication stacks can threaten availability and integrity of grid and utility operations. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trianglemicroworks over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2186CRITICAL On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send a specially crafted broadcast message including format string characters to the | Jun 7, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-0369HIGH Triangle MicroWorks SCADA Data Gateway Restore Workspace Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co | May 7, 2024 | 8.8 | 27 | NO | NO |
CVE-2023-39457CRITICAL Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Triang | May 3, 2024 | 9.8 | 27 | NO | NO |
CVE-2020-10611CRITICAL Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to execute arbitrary code due to the lack of proper validation o | Apr 15, 2020 | 9.8 | 26 | NO | NO |
CVE-2022-38138HIGH The Triangle Microworks IEC 61850 Library (Any client or server using the C language library with a version number of 11.2.0 or earlier and any client or server using the C++, C#, | Oct 11, 2022 | 7.5 | 24 | NO | NO |
CVE-2020-6996CRITICAL Triangle MicroWorks DNP3 Outstation LibrariesDNP3 Outstation .NET Protocol components and DNP3 Outstation ANSI C source code libraries are affected:3.16.00 through 3.25.01. A speci | Apr 15, 2020 | 9.8 | 24 | NO | NO |
CVE-2024-34057HIGH Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing received messages. The resulting buffer overflow can cause a c | Sep 18, 2024 | 7.5 | 21 | NO | NO |
CVE-2023-39464HIGH Triangle MicroWorks SCADA Data Gateway GTWWebMonitorService Unquoted Search Path Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute code on | May 3, 2024 | 7.2 | 21 | NO | NO |
CVE-2023-39460HIGH Triangle MicroWorks SCADA Data Gateway Event Log Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on | May 3, 2024 | 7.2 | 21 | NO | NO |
CVE-2023-39459HIGH Triangle MicroWorks SCADA Data Gateway Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected i | May 3, 2024 | 7.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trianglemicroworks.
Media articles that mention a CVE ID that affects a product developed by Trianglemicroworks — matched by CVE ID, not by vendor name.