Back

HIGH

Ecava IntegraXor Exposure of Access Control List Files to an Unauthorized Control Sphere

Published Jan 9, 2014

Description

The SCADA server in Ecava IntegraXor before 4.1.4369 allows remote attackers to read arbitrary project backup files via a crafted URL.

Affected products

Remediation

Vendor solution

Ecava Sdn Bhd has issued a customer notification that details this vulnerability and provides mitigations to its customers. Ecava Sdn Bhd recommends users download and install the update, IntegraXor SCADA Server 4.1.4369, from their support Web site:  http://www.integraxor.com/download/beta.msi?4.1.4369

For additional information, please see Ecava’s vulnerability note:  http://www.integraxor.com/blog/category/security/vulnerability-note/

Metrics

Weaknesses (2)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Jan 9, 2014
Updated Aug 22, 2025
Reserved Jan 2, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a