{"api_version":"1","generated_at":"2026-07-23T08:14:44+00:00","cve":"CVE-2014-0786","urls":{"html":"https://cve.report/CVE-2014-0786","api":"https://cve.report/api/cve/CVE-2014-0786.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-0786","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-0786"},"summary":{"title":"Ecava IntegraXor Information Exposure","description":"Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via SELECT statements that leverage the guest role.","state":"PUBLISHED","assigner":"icscert","published_at":"2014-05-01 01:56:10","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-200","CWE-310","CWE-200 CWE-200"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"ics-cert@hq.dhs.gov","type":"Secondary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}},{"version":"2.0","source":"CNA","type":"CVSS","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"accessComplexity":"LOW","accessVector":"NETWORK","authentication":"NONE","availabilityImpact":"PARTIAL","baseScore":7.5,"confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","version":"2.0"}}],"references":[{"url":"http://www.integraxor.com/blog/category/security/vulnerability-note/","name":"http://www.integraxor.com/blog/category/security/vulnerability-note/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IntegraXor HMI/SCADA • Free Web SCADA for 128 Modbus I/O","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-091-01","name":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-091-01","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://ics-cert.us-cert.gov/advisories/ICSA-14-091-01","name":"http://ics-cert.us-cert.gov/advisories/ICSA-14-091-01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","US Government Resource"],"title":"Ecava IntegraXor Guest Account Information Disclosure Vulnerability | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-224-01","name":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-224-01","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-0786","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0786","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Ecava","product":"IntegraXor","version":"affected 4.1.4410 custom","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"A customer notification from Ecava has been issued that details this vulnerability and provides mitigation guidance to its customers. Ecava recommends users download and install the update, IntegraXor SCADA Server 4.1.4410, from their support web site:  http://www.integraxor.com/download/igsetup.msi?4.1.4410 \n\nFor additional information, please see Ecava’s vulnerability note:  http://www.integraxor.com/blog/category/security/vulnerability-note/","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Andrea Micalizzi","lang":"en"}],"nvd_cpes":[{"cve_year":"2014","cve_id":"786","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"4.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"786","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"4.1.4340","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"786","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"4.1.4360","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"786","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"4.1.4369","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"786","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"4.1.4380","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"786","vulnerable":"1","versionEndIncluding":"4.1.4390","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ecava","cpe5":"integraxor","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T09:27:19.465Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.integraxor.com/blog/category/security/vulnerability-note/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://ics-cert.us-cert.gov/advisories/ICSA-14-091-01"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"IntegraXor","vendor":"Ecava","versions":[{"lessThan":"4.1.4410","status":"affected","version":"0","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"Andrea Micalizzi"}],"datePublic":"2014-04-29T06:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via SELECT statements that leverage the guest role.</p>"}],"value":"Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via SELECT statements that leverage the guest role."}],"metrics":[{"cvssV2_0":{"accessComplexity":"LOW","accessVector":"NETWORK","authentication":"NONE","availabilityImpact":"PARTIAL","baseScore":7.5,"confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","version":"2.0"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-200","description":"CWE-200","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-10-13T22:50:30.946Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.integraxor.com/blog/category/security/vulnerability-note/"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-091-01"},{"url":"http://www.integraxor.com/blog/category/security/vulnerability-note/"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-224-01"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>A customer notification from Ecava has been issued that details this vulnerability and provides mitigation guidance to its customers. Ecava recommends users download and install the update, IntegraXor SCADA Server 4.1.4410, from their support web site:&nbsp;<a target=\"_blank\" rel=\"nofollow\" href=\"http://www.integraxor.com/download/igsetup.msi?4.1.4410\">http://www.integraxor.com/download/igsetup.msi?4.1.4410</a></p><p>For additional information, please see Ecava’s vulnerability note:&nbsp;<a target=\"_blank\" rel=\"nofollow\" href=\"http://www.integraxor.com/blog/category/security/vulnerability-note/\">http://www.integraxor.com/blog/category/security/vulnerability-note/</a></p>\n\n<br>"}],"value":"A customer notification from Ecava has been issued that details this vulnerability and provides mitigation guidance to its customers. Ecava recommends users download and install the update, IntegraXor SCADA Server 4.1.4410, from their support web site:  http://www.integraxor.com/download/igsetup.msi?4.1.4410 \n\nFor additional information, please see Ecava’s vulnerability note:  http://www.integraxor.com/blog/category/security/vulnerability-note/"}],"source":{"advisory":"ICSA-14-091-01","discovery":"EXTERNAL"},"title":"Ecava IntegraXor Information Exposure","x_generator":{"engine":"Vulnogram 0.2.0"},"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2014-0786","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via SELECT statements that leverage the guest role."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.integraxor.com/blog/category/security/vulnerability-note/","refsource":"CONFIRM","url":"http://www.integraxor.com/blog/category/security/vulnerability-note/"},{"name":"http://ics-cert.us-cert.gov/advisories/ICSA-14-091-01","refsource":"MISC","url":"http://ics-cert.us-cert.gov/advisories/ICSA-14-091-01"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2014-0786","datePublished":"2014-05-01T01:00:00.000Z","dateReserved":"2014-01-02T00:00:00.000Z","dateUpdated":"2025-10-13T22:50:30.946Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-05-01 01:56:10","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-200","CWE-310","CWE-200 CWE-200"],"metrics":{"cvssMetricV2":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:*:*:*:*:*:*:*:*","versionEndIncluding":"4.1.4390","matchCriteriaId":"40E2214C-80FC-4973-BF67-1ECFC1C5D303"},{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:4.1:*:*:*:*:*:*:*","matchCriteriaId":"6C254168-384E-4B0A-BB22-445D7281FAC8"},{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:4.1.4340:*:*:*:*:*:*:*","matchCriteriaId":"E1223B72-A344-450E-8E10-1B704DF894BB"},{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:4.1.4360:*:*:*:*:*:*:*","matchCriteriaId":"B0319EBA-C39F-4A3D-AF40-7A90FA016696"},{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:4.1.4369:*:*:*:*:*:*:*","matchCriteriaId":"5EA3EDD6-3459-4916-B184-271A43FAC10A"},{"vulnerable":true,"criteria":"cpe:2.3:a:ecava:integraxor:4.1.4380:*:*:*:*:*:*:*","matchCriteriaId":"C4C3DBE0-50B6-4A39-9FA5-878951AD855E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"786","Ordinal":"1","Title":"Ecava IntegraXor Information Exposure","CVE":"CVE-2014-0786","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"786","Ordinal":"1","NoteData":"Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via SELECT statements that leverage the guest role.","Type":"Description","Title":"Ecava IntegraXor Information Exposure"},{"CveYear":"2014","CveId":"786","Ordinal":"2","NoteData":"2014-04-30","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"786","Ordinal":"3","NoteData":"2014-04-30","Type":"Other","Title":"Modified"}]}}}