CVE Vulnerabilities

CVE-2014-0752

Exposure of Access Control List Files to an Unauthorized Control Sphere

Published: Jan 09, 2014 | Modified: Aug 22, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The SCADA server in Ecava IntegraXor before 4.1.4369 allows remote attackers to read arbitrary project backup files via a crafted URL.

Weakness

The product stores access control list files in a directory or other container that is accessible to actors outside of the intended control sphere.

Affected Software

NameVendorStart VersionEnd Version
IntegraxorEcava*4.1.4360 (including)
IntegraxorEcava3.5.3900.5 (including)3.5.3900.5 (including)
IntegraxorEcava3.5.3900.10 (including)3.5.3900.10 (including)
IntegraxorEcava3.6.4000.0 (including)3.6.4000.0 (including)
IntegraxorEcava3.60.4061 (including)3.60.4061 (including)
IntegraxorEcava3.71 (including)3.71 (including)
IntegraxorEcava3.71.4200 (including)3.71.4200 (including)
IntegraxorEcava3.72 (including)3.72 (including)
IntegraxorEcava4.00 (including)4.00 (including)
IntegraxorEcava4.1 (including)4.1 (including)

Potential Mitigations

References