Integer overflow in Trihedral Engineering VTScada (formerly VTS) 6.5 through 9.x before 9.1.20, 10.x before 10.2.22, and 11.x before 11.1.07 allows remote attackers to cause a denial of service (server crash) via a crafted request, which triggers a large memory allocation.
Advisories
Source ID Title
EUVD EUVD EUVD-2014-9017 Integer overflow in Trihedral Engineering VTScada (formerly VTS) 6.5 through 9.x before 9.1.20, 10.x before 10.2.22, and 11.x before 11.1.07 allows remote attackers to cause a denial of service (server crash) via a crafted request, which triggers a large memory allocation.
Fixes

Solution

Trihedral Engineering Limited has created three updated versions of software. These software updates are available from Trihedral Engineering Ltd.’s FTP site: ftp://ftp.trihedral.com/VTS/ Version Information: * 11.1.09 – Latest build including newest features and fixes. Any installation key with a maintenance expiration date after January 1, 2014, will work this installation. * 10.2.22 –Recommended for all users of VTS 10. Any installation key with a maintenance expiration date after December 1, 2010, will work with this installation. * 09.1.20 – Recommended for all users prior to 10.0. Any installation key with a maintenance expiration date after December 1, 2009, will work with this installation. Help file notes for upgrading VTScada/VTS can be found at:  http://www.trihedral.com/help/#Op_Welcome/Wel_UpgradeNotes.htm If you have any questions or any difficulties with installing one of these updates, please call Trihedral Tech Support: 1-855-887-2232 1-902-835-1575 +44 (0) 1224 258910 for the United Kingdom


Workaround

No workaround given by the vendor.

History

Fri, 25 Jul 2025 17:00:00 +0000

Type Values Removed Values Added
Title Trihedral Engineering Limited VTScada Integer Overflow
Weaknesses CWE-190
References
Metrics cvssV2_0

{'score': 5.0, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P'}

cvssV2_0

{'score': 7.8, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-07-25T16:46:02.667Z

Reserved: 2014-12-02T00:00:00

Link: CVE-2014-9192

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-12-11T15:59:04.773

Modified: 2025-07-25T17:15:27.680

Link: CVE-2014-9192

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.