CVE-2014-9192

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
11/12/2014
Last modified:
25/07/2025

Description

Integer overflow in Trihedral Engineering VTScada (formerly VTS) 6.5 through 9.x before 9.1.20, 10.x before 10.2.22, and 11.x before 11.1.07 allows remote attackers to cause a denial of service (server crash) via a crafted request, which triggers a large memory allocation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:trihedral:vtscada:*:*:*:*:*:*:*:* 6.5 (including) 9.1.20 (excluding)
cpe:2.3:a:trihedral:vtscada:*:*:*:*:*:*:*:* 10.0 (including) 10.2.22 (excluding)
cpe:2.3:a:trihedral:vtscada:*:*:*:*:*:*:*:* 11.0 (including) 11.1.07 (excluding)