Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Trianglemicroworks

First CVE: Sep 9, 2013Active for: 13 yearsTotal CVEs: 25
30.5
VTI Score
Low

Trianglemicroworks develops supervisory control and data acquisition (SCADA) components and industrial communications libraries, including DNP3 and IEC 60870-5 protocol implementations and gateway products, that operate in critical infrastructure and utility networks. While the vendor's product portfolio is narrow, its libraries and protocol stacks achieve broad deployment as embedded components across industrial control systems and third-party integrations, placing it among the more prominent vendors in critical-infrastructure vulnerability tracking. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes including path traversal, missing authentication, improper input validation, memory-bounds violations, and out-of-bounds writes that reflect both the protocol-parsing complexity and the operational-technology deployment context of SCADA components. Defenders should prioritize inventory and patching of affected SCADA gateways and systems that incorporate this vendor's protocol libraries, as flaws in industrial communication stacks can threaten availability and integrity of grid and utility operations. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Trianglemicroworks over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 9, 2013
12 years ago
Most Recent CVE
Sep 18, 2024
674 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-2186CRITICAL
On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send a specially crafted broadcast message including format string characters to the
Jun 7, 20239.829NONO
CVE-2022-0369HIGH
Triangle MicroWorks SCADA Data Gateway Restore Workspace Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co
May 7, 20248.827NONO
CVE-2023-39457CRITICAL
Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Triang
May 3, 20249.827NONO
CVE-2020-10611CRITICAL
Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to execute arbitrary code due to the lack of proper validation o
Apr 15, 20209.826NONO
CVE-2022-38138HIGH
The Triangle Microworks IEC 61850 Library (Any client or server using the C language library with a version number of 11.2.0 or earlier and any client or server using the C++, C#,
Oct 11, 20227.524NONO
CVE-2020-6996CRITICAL
Triangle MicroWorks DNP3 Outstation LibrariesDNP3 Outstation .NET Protocol components and DNP3 Outstation ANSI C source code libraries are affected:3.16.00 through 3.25.01. A speci
Apr 15, 20209.824NONO
CVE-2024-34057HIGH
Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing received messages. The resulting buffer overflow can cause a c
Sep 18, 20247.521NONO
CVE-2023-39464HIGH
Triangle MicroWorks SCADA Data Gateway GTWWebMonitorService Unquoted Search Path Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute code on
May 3, 20247.221NONO
CVE-2023-39460HIGH
Triangle MicroWorks SCADA Data Gateway Event Log Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on
May 3, 20247.221NONO
CVE-2023-39459HIGH
Triangle MicroWorks SCADA Data Gateway Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected i
May 3, 20247.821NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
32%
48%
16%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (4.0%)
Network19 (76.0%)
Unknown4 (16.0%)
Physical0 (0.0%)
Adjacent Network1 (4.0%)
Attack Complexity
Low19 (76.0%)
High2 (8.0%)
Unknown4 (16.0%)
User Interaction
None20 (80.0%)
Unknown4 (16.0%)
Required1 (4.0%)
Privileges Required
Low2 (8.0%)
High5 (20.0%)
None14 (56.0%)
Unknown4 (16.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Trianglemicroworks.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Trianglemicroworks — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Trianglemicroworks's Products

View all 4 CNAs →

Top CWEs