Back

HIGH

Trihedral Engineering Limited VTScada Integer Overflow

Published Dec 11, 2014

Description

Integer overflow in Trihedral Engineering VTScada (formerly VTS) 6.5 through 9.x before 9.1.20, 10.x before 10.2.22, and 11.x before 11.1.07 allows remote attackers to cause a denial of service (server crash) via a crafted request, which triggers a large memory allocation.

Affected products

Remediation

Vendor solution

Trihedral Engineering Limited has created three updated versions of software. These software updates are available from Trihedral Engineering Ltd.’s FTP site: ftp://ftp.trihedral.com/VTS/

Version Information:

* 11.1.09 – Latest build including newest features and fixes. Any installation key with a maintenance expiration date after January 1, 2014, will work this installation.

* 10.2.22 –Recommended for all users of VTS 10. Any installation key with a maintenance expiration date after December 1, 2010, will work with this installation.

* 09.1.20 – Recommended for all users prior to 10.0. Any installation key with a maintenance expiration date after December 1, 2009, will work with this installation.

Help file notes for upgrading VTScada/VTS can be found at:  http://www.trihedral.com/help/#Op_Welcome/Wel_UpgradeNotes.htm

If you have any questions or any difficulties with installing one of these updates, please call Trihedral Tech Support: 1-855-887-2232 1-902-835-1575 +44 (0) 1224 258910 for the United Kingdom

Metrics

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Dec 11, 2014
Updated Jul 25, 2025
Reserved Dec 2, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a