Ecava IntegraXor Exposure of Access Control List Files to an Unauthorized Control Sphere
Summary
| CVE | CVE-2014-0752 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-01-09 18:07:26 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The SCADA server in Ecava IntegraXor before 4.1.4369 allows remote attackers to read arbitrary project backup files via a crafted URL. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS: 0.025620000 probability, percentile 0.855810000 (date 2026-04-30)
Problem Types: CWE-529 | CWE-264 | CWE-529 CWE-529
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:P/I:N/A:N | |
| 2.0 | [email protected] | Secondary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P | |
| 2.0 | CNA | CVSS | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ecava | Integraxor | 3.5.3900.10 | All | All | All |
| Application | Ecava | Integraxor | 3.5.3900.5 | All | All | All |
| Application | Ecava | Integraxor | 3.6.4000.0 | All | All | All |
| Application | Ecava | Integraxor | 3.60.4061 | All | All | All |
| Application | Ecava | Integraxor | 3.71 | All | All | All |
| Application | Ecava | Integraxor | 3.71.4200 | All | All | All |
| Application | Ecava | Integraxor | 3.72 | All | All | All |
| Application | Ecava | Integraxor | 4.00 | All | All | All |
| Application | Ecava | Integraxor | 4.1 | All | All | All |
| Application | Ecava | Integraxor | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Ecava | IntegraXor | affected 4.1.4360 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IntegraXor HMI/SCADA • Free Web SCADA for 128 Modbus I/O | af854a3a-2127-422b-91ae-364da2661108 | www.integraxor.com | Patch, Vendor Advisory |
| www.cisa.gov/news-events/ics-advisories/icsa-14-008-01 | [email protected] | www.cisa.gov | |
| Ecava Sdn Bhd IntegraXor Project Directory Information Disclosure Vulnerability | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Patch, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Zero Day Initiative (en)
Additional Advisory Data
Solutions
CNA: Ecava Sdn Bhd has issued a customer notification that details this vulnerability and provides mitigations to its customers. Ecava Sdn Bhd recommends users download and install the update, IntegraXor SCADA Server 4.1.4369, from their support Web site: http://www.integraxor.com/download/beta.msi?4.1.4369 For additional information, please see Ecava’s vulnerability note: http://www.integraxor.com/blog/category/security/vulnerability-note/
There are currently no legacy QID mappings associated with this CVE.