CVE Vulnerabilities

CVE-2014-0752

Exposure of Access Control List Files to an Unauthorized Control Sphere

Published: Jan 09, 2014 | Modified: Aug 22, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The SCADA server in Ecava IntegraXor before 4.1.4369 allows remote attackers to read arbitrary project backup files via a crafted URL.

Weakness

The product stores access control list files in a directory or other container that is accessible to actors outside of the intended control sphere.

Affected Software

Name Vendor Start Version End Version
Integraxor Ecava * 4.1.4360 (including)
Integraxor Ecava 3.5.3900.5 (including) 3.5.3900.5 (including)
Integraxor Ecava 3.5.3900.10 (including) 3.5.3900.10 (including)
Integraxor Ecava 3.6.4000.0 (including) 3.6.4000.0 (including)
Integraxor Ecava 3.60.4061 (including) 3.60.4061 (including)
Integraxor Ecava 3.71 (including) 3.71 (including)
Integraxor Ecava 3.71.4200 (including) 3.71.4200 (including)
Integraxor Ecava 3.72 (including) 3.72 (including)
Integraxor Ecava 4.00 (including) 4.00 (including)
Integraxor Ecava 4.1 (including) 4.1 (including)

Potential Mitigations

References