Trihedral's vulnerability footprint concentrates in its VTScada industrial control and SCADA visualization platform, a niche but operationally critical product deployed across utilities and manufacturing environments. The vendor's disclosures skew toward serious outcomes and have a moderate tendency toward confirmed in-the-wild exploitation; the recurring weakness classes—including information exposure through directory listings, improper access control, weak authentication, and input validation gaps—reflect the web-facing and networked nature of the platform and its exposure to both internal and external threat actors. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trihedral over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-4523HIGH The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bounds read and application crash | Jun 9, 2016 | 7.5 | 77 | YES | NO |
CVE-2016-4532CRITICAL Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to read arbitrary files via a cra | Jun 9, 2016 | 9.1 | 43 | NO | NO |
CVE-2016-4510CRITICAL The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to bypass authentication and read arbitrary files via unspecified vect | Jun 9, 2016 | 9.1 | 37 | NO | NO |
CVE-2022-3181HIGH An Improper Input Validation vulnerability exists in Trihedral VTScada version 12.0.38 and prior. A specifically malformed HTTP request could cause the affected VTScada to crash. B | Nov 2, 2022 | 7.5 | 24 | NO | NO |
CVE-2017-14031HIGH An Improper Access Control issue was discovered in Trihedral VTScada 11.3.03 and prior. A local, non-administrator user has privileges to read and write to the file system of the t | Nov 6, 2017 | 7.8 | 24 | NO | NO |
CVE-2017-14029HIGH An Uncontrolled Search Path Element issue was discovered in Trihedral VTScada 11.3.03 and prior. The program will execute specially crafted malicious dll files placed on the target | Nov 6, 2017 | 7.8 | 24 | NO | NO |
CVE-2017-6045HIGH An Information Exposure issue was discovered in Trihedral VTScada Versions prior to 11.2.26. Some files are exposed within the web server application to unauthenticated users. Thes | Jun 21, 2017 | 7.5 | 24 | NO | NO |
CVE-2017-6043HIGH A Resource Consumption issue was discovered in Trihedral VTScada Versions prior to 11.2.26. The client does not properly validate the input or limit the amount of resources that ar | Jun 21, 2017 | 7.5 | 23 | NO | NO |
CVE-2017-6053MEDIUM A Cross-Site Scripting issue was discovered in Trihedral VTScada Versions prior to 11.2.26. A cross-site scripting vulnerability may allow JavaScript code supplied by the attacker | Jun 21, 2017 | 6.1 | 21 | NO | NO |
CVE-2014-9192MEDIUM Integer overflow in Trihedral Engineering VTScada (formerly VTS) 6.5 through 9.x before 9.1.20, 10.x before 10.2.22, and 11.x before 11.1.07 allows remote attackers to cause a deni | Dec 11, 2014 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trihedral.
Media articles that mention a CVE ID that affects a product developed by Trihedral — matched by CVE ID, not by vendor name.