Ecava IntegraXor Information Exposure
Summary
| CVE | CVE-2014-0786 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-05-01 01:56:10 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via SELECT statements that leverage the guest role. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
Problem Types: CWE-200 | CWE-310 | CWE-200 CWE-200
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:P/I:N/A:N | |
| 2.0 | [email protected] | Secondary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P | |
| 2.0 | CNA | CVSS | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ecava | Integraxor | 4.1 | All | All | All |
| Application | Ecava | Integraxor | 4.1.4340 | All | All | All |
| Application | Ecava | Integraxor | 4.1.4360 | All | All | All |
| Application | Ecava | Integraxor | 4.1.4369 | All | All | All |
| Application | Ecava | Integraxor | 4.1.4380 | All | All | All |
| Application | Ecava | Integraxor | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Ecava | IntegraXor | affected 4.1.4410 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IntegraXor HMI/SCADA • Free Web SCADA for 128 Modbus I/O | af854a3a-2127-422b-91ae-364da2661108 | www.integraxor.com | Vendor Advisory |
| www.cisa.gov/news-events/ics-advisories/icsa-14-091-01 | [email protected] | www.cisa.gov | |
| Ecava IntegraXor Guest Account Information Disclosure Vulnerability | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Patch, US Government Resource |
| www.cisa.gov/news-events/ics-advisories/icsa-14-224-01 | [email protected] | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Andrea Micalizzi (en)
Additional Advisory Data
Solutions
CNA: A customer notification from Ecava has been issued that details this vulnerability and provides mitigation guidance to its customers. Ecava recommends users download and install the update, IntegraXor SCADA Server 4.1.4410, from their support web site: http://www.integraxor.com/download/igsetup.msi?4.1.4410 For additional information, please see Ecava’s vulnerability note: http://www.integraxor.com/blog/category/security/vulnerability-note/
There are currently no legacy QID mappings associated with this CVE.