Ecava IntegraXor Stack-based Buffer Overflow
Summary
| CVE | CVE-2014-0753 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-01-21 01:55:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Stack-based buffer overflow in the SCADA server in Ecava IntegraXor before 4.1.4390 allows remote attackers to cause a denial of service (system crash) by triggering access to DLL code located in the IntegraXor directory. |
Risk And Classification
Primary CVSS: v2.0 7.8 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:C
EPSS: 0.031170000 probability, percentile 0.868970000 (date 2026-05-03)
Problem Types: CWE-121 | CWE-119 | CWE-121 CWE-121
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 7.8 | AV:N/AC:L/Au:N/C:N/I:N/A:C | |
| 2.0 | [email protected] | Secondary | 7.8 | AV:N/AC:L/Au:N/C:N/I:N/A:C | |
| 2.0 | CNA | CVSS | 7.8 | AV:N/AC:L/Au:N/C:N/I:N/A:C |
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:L/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ecava | Integraxor | 3.5.3900.10 | All | All | All |
| Application | Ecava | Integraxor | 3.5.3900.5 | All | All | All |
| Application | Ecava | Integraxor | 3.6.4000.0 | All | All | All |
| Application | Ecava | Integraxor | 3.60.4061 | All | All | All |
| Application | Ecava | Integraxor | 3.71 | All | All | All |
| Application | Ecava | Integraxor | 3.71.4200 | All | All | All |
| Application | Ecava | Integraxor | 3.72 | All | All | All |
| Application | Ecava | Integraxor | 4.00 | All | All | All |
| Application | Ecava | Integraxor | 4.1 | All | All | All |
| Application | Ecava | Integraxor | 4.1.4360 | All | All | All |
| Application | Ecava | Integraxor | 4.1.4369 | All | All | All |
| Application | Ecava | Integraxor | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Ecava | IntegraXor | affected 4.1.4380 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IntegraXor HMI/SCADA System • Web SCADA with fully functional & free SCADA development tools | af854a3a-2127-422b-91ae-364da2661108 | www.integraxor.com | Patch, Vendor Advisory |
| Ecava IntegraXor Buffer Overflow Vulnerability | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| www.cisa.gov/news-events/ics-advisories/icsa-14-016-01 | [email protected] | www.cisa.gov | |
| osvdb.org/102171 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Luigi Auriemma (en)
Additional Advisory Data
Solutions
CNA: Ecava Sdn Bhd has issued a customer notification that details this vulnerability and provides mitigation guidance to its customers. Ecava Sdn Bhd recommends users download and install the update, IntegraXor SCADA Server 4.1.4390, from their support Web site: http://www.integraxor.com/download/rc.msi?4.1.4390 For additional information, please see Ecava’s vulnerability note: http://www.integraxor.com/blog/buffer-overflow-vulnerability-note/
There are currently no legacy QID mappings associated with this CVE.