E16-6hn01
CVSS:
7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
False Positive:
f
Variants:
5
Year:
2016
Description
This strike exploits a vulnerability in Trihedral VTScada. Specifically the program does not properly handle HTTP requests made to the target with directory traversal characters. If several of these characters are sent to the target, an out of bounds indexing error occurs. This will crash the vtscada application, and can potentially lead to remote code execution.
CVE
References
https://ics-cert.us-cert.gov/advisories/ICSA-16-159-01