{"api_version":"1","generated_at":"2026-07-23T07:39:20+00:00","cve":"CVE-2014-0753","urls":{"html":"https://cve.report/CVE-2014-0753","api":"https://cve.report/api/cve/CVE-2014-0753.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-0753","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-0753"},"summary":{"title":"Ecava IntegraXor Stack-based Buffer Overflow","description":"Stack-based buffer overflow in the SCADA server in Ecava IntegraXor before 4.1.4390 allows remote attackers to cause a denial of service (system crash) by triggering access to DLL code located in the IntegraXor directory.","state":"PUBLISHED","assigner":"icscert","published_at":"2014-01-21 01:55:03","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-121","CWE-119","CWE-121 CWE-121"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"}},{"version":"2.0","source":"ics-cert@hq.dhs.gov","type":"Secondary","score":"7.8","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"}},{"version":"2.0","source":"CNA","type":"CVSS","score":"7.8","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","data":{"accessComplexity":"LOW","accessVector":"NETWORK","authentication":"NONE","availabilityImpact":"COMPLETE","baseScore":7.8,"confidentialityImpact":"NONE","integrityImpact":"NONE","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","version":"2.0"}}],"references":[{"url":"http://www.integraxor.com/blog/buffer-overflow-vulnerability-note/","name":"http://www.integraxor.com/blog/buffer-overflow-vulnerability-note/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"IntegraXor HMI/SCADA System • Web SCADA with fully functional & free SCADA development tools","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://ics-cert.us-cert.gov/advisories/ICSA-14-016-01","name":"http://ics-cert.us-cert.gov/advisories/ICSA-14-016-01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"Ecava IntegraXor Buffer Overflow Vulnerability | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-016-01","name":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-016-01","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://osvdb.org/102171","name":"http://osvdb.org/102171","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-0753","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0753","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Ecava","product":"IntegraXor","version":"affected 4.1.4380 custom","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Ecava Sdn Bhd has issued a customer notification that details this \nvulnerability and provides mitigation guidance to its customers. Ecava \nSdn Bhd recommends users download and install the update, IntegraXor \nSCADA Server 4.1.4390, from their support Web site:\n\n\n http://www.integraxor.com/download/rc.msi?4.1.4390 \n\nFor additional information, please see Ecava’s vulnerability note:\n\n\n http://www.integraxor.com/blog/buffer-overflow-vulnerability-note/","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Luigi Auriemma","lang":"en"}],"nvd_cpes":[{"cve_year":"2014","cve_id":"753","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"3.5.3900.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"753","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"3.5.3900.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"753","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"3.6.4000.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"753","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"3.60.4061","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"753","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"3.71","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"753","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"3.71.4200","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"753","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"3.72","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"753","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"4.00","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"753","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"4.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"753","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"4.1.4360","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"753","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"4.1.4369","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"753","vulnerable":"1","versionEndIncluding":"4.1.4380","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2014","cve_id":"753","cve":"CVE-2014-0753","epss":"0.031170000","percentile":"0.868970000","score_date":"2026-05-03","updated_at":"2026-05-04 00:13:06"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T09:27:19.521Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"102171","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/102171"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.integraxor.com/blog/buffer-overflow-vulnerability-note/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://ics-cert.us-cert.gov/advisories/ICSA-14-016-01"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"IntegraXor","vendor":"Ecava","versions":[{"lessThanOrEqual":"4.1.4380","status":"affected","version":"0","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"Luigi Auriemma"}],"datePublic":"2014-01-15T07:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Stack-based buffer overflow in the SCADA server in Ecava IntegraXor before 4.1.4390 allows remote attackers to cause a denial of service (system crash) by triggering access to DLL code located in the IntegraXor directory.</p>"}],"value":"Stack-based buffer overflow in the SCADA server in Ecava IntegraXor before 4.1.4390 allows remote attackers to cause a denial of service (system crash) by triggering access to DLL code located in the IntegraXor directory."}],"metrics":[{"cvssV2_0":{"accessComplexity":"LOW","accessVector":"NETWORK","authentication":"NONE","availabilityImpact":"COMPLETE","baseScore":7.8,"confidentialityImpact":"NONE","integrityImpact":"NONE","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","version":"2.0"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-121","description":"CWE-121","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-08-25T23:46:30.088Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"name":"102171","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/102171"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.integraxor.com/blog/buffer-overflow-vulnerability-note/"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-016-01"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Ecava Sdn Bhd has issued a customer notification that details this \nvulnerability and provides mitigation guidance to its customers. Ecava \nSdn Bhd recommends users download and install the update, IntegraXor \nSCADA Server 4.1.4390, from their support Web site:</p>\n<p><a target=\"_blank\" rel=\"nofollow\" href=\"http://www.integraxor.com/download/rc.msi?4.1.4390\">http://www.integraxor.com/download/rc.msi?4.1.4390</a></p><p>For additional information, please see Ecava’s vulnerability note:</p>\n<p><a target=\"_blank\" rel=\"nofollow\" href=\"http://www.integraxor.com/blog/buffer-overflow-vulnerability-note/\">http://www.integraxor.com/blog/buffer-overflow-vulnerability-note/</a></p>\n\n<br>"}],"value":"Ecava Sdn Bhd has issued a customer notification that details this \nvulnerability and provides mitigation guidance to its customers. Ecava \nSdn Bhd recommends users download and install the update, IntegraXor \nSCADA Server 4.1.4390, from their support Web site:\n\n\n http://www.integraxor.com/download/rc.msi?4.1.4390 \n\nFor additional information, please see Ecava’s vulnerability note:\n\n\n http://www.integraxor.com/blog/buffer-overflow-vulnerability-note/"}],"source":{"advisory":"ICSA-14-016-01","discovery":"EXTERNAL"},"title":"Ecava IntegraXor Stack-based Buffer Overflow","x_generator":{"engine":"Vulnogram 0.2.0"},"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2014-0753","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in the SCADA server in Ecava IntegraXor before 4.1.4390 allows remote attackers to cause a denial of service (system crash) by triggering access to DLL code located in the IntegraXor directory."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"102171","refsource":"OSVDB","url":"http://osvdb.org/102171"},{"name":"http://www.integraxor.com/blog/buffer-overflow-vulnerability-note/","refsource":"CONFIRM","url":"http://www.integraxor.com/blog/buffer-overflow-vulnerability-note/"},{"name":"http://ics-cert.us-cert.gov/advisories/ICSA-14-016-01","refsource":"MISC","url":"http://ics-cert.us-cert.gov/advisories/ICSA-14-016-01"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2014-0753","datePublished":"2014-01-21T01:00:00.000Z","dateReserved":"2014-01-02T00:00:00.000Z","dateUpdated":"2025-08-25T23:46:30.088Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-01-21 01:55:03","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-121","CWE-119","CWE-121 CWE-121"],"metrics":{"cvssMetricV2":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:*:*:*:*:*:*:*:*","versionEndIncluding":"4.1.4380","matchCriteriaId":"D4C53150-2600-425B-BACB-51111E97664F"},{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:3.5.3900.5:*:*:*:*:*:*:*","matchCriteriaId":"024F3AE4-4912-4C4C-859E-3CC832123394"},{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:3.5.3900.10:*:*:*:*:*:*:*","matchCriteriaId":"8E4BEE8F-B1FC-47E0-BF7F-3247A29CCBFF"},{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:3.6.4000.0:*:*:*:*:*:*:*","matchCriteriaId":"B0EB4452-4772-4CA9-A119-A8DFE183CB87"},{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:3.60.4061:*:*:*:*:*:*:*","matchCriteriaId":"66CE22B5-F6B1-4CA5-8975-A0DEA0272E10"},{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:3.71:*:*:*:*:*:*:*","matchCriteriaId":"8C338B7E-B958-4ED4-AF3C-B64A72CA01A6"},{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:3.71.4200:*:*:*:*:*:*:*","matchCriteriaId":"B6BE9299-0D5D-4FDF-8E5C-17EBB3E3D895"},{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:3.72:*:*:*:*:*:*:*","matchCriteriaId":"C4717F90-420C-40C1-B465-2052F5F5D8F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:4.00:*:*:*:*:*:*:*","matchCriteriaId":"04D6E69A-AE18-4B23-95CA-85C605E5F23B"},{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:4.1:*:*:*:*:*:*:*","matchCriteriaId":"6C254168-384E-4B0A-BB22-445D7281FAC8"},{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:4.1.4360:*:*:*:*:*:*:*","matchCriteriaId":"B0319EBA-C39F-4A3D-AF40-7A90FA016696"},{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:4.1.4369:*:*:*:*:*:*:*","matchCriteriaId":"5EA3EDD6-3459-4916-B184-271A43FAC10A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"753","Ordinal":"1","Title":"Ecava IntegraXor Stack-based Buffer Overflow","CVE":"CVE-2014-0753","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"753","Ordinal":"1","NoteData":"Stack-based buffer overflow in the SCADA server in Ecava IntegraXor before 4.1.4390 allows remote attackers to cause a denial of service (system crash) by triggering access to DLL code located in the IntegraXor directory.","Type":"Description","Title":"Ecava IntegraXor Stack-based Buffer Overflow"},{"CveYear":"2014","CveId":"753","Ordinal":"2","NoteData":"2014-01-20","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"753","Ordinal":"3","NoteData":"2015-08-17","Type":"Other","Title":"Modified"}]}}}