CVE-2017-14029

HIGH

Trihedral VTScada <11.3.03 - Code Injection

Title source: llm
STIX 2.1

Description

An Uncontrolled Search Path Element issue was discovered in Trihedral VTScada 11.3.03 and prior. The program will execute specially crafted malicious dll files placed on the target machine.

References (1)

Core 1
Core References
Issue Tracking, Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-17-304-02

Scores

CVSS v3 7.8
EPSS 0.0093
EPSS Percentile 55.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-427
Status published
Products (2)
n/a/Trihedral Engineering Limited VTScada Trihedral Engineering Limited VTScada
trihedral/vtscada < 11.3.03
Published Nov 06, 2017
Tracked Since Feb 18, 2026