7.5

CVE-2014-0752

The SCADA server in Ecava IntegraXor before 4.1.4369 allows remote attackers to read arbitrary project backup files via a crafted URL.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EcavaIntegraxor Version <= 4.1.4360
EcavaIntegraxor Version3.5.3900.5
EcavaIntegraxor Version3.5.3900.10
EcavaIntegraxor Version3.6.4000.0
EcavaIntegraxor Version3.60.4061
EcavaIntegraxor Version3.71
EcavaIntegraxor Version3.71.4200
EcavaIntegraxor Version3.72
EcavaIntegraxor Version4.00
EcavaIntegraxor Version4.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.56% 0.852
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
ics-cert@hq.dhs.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-529 Exposure of Access Control List Files to an Unauthorized Control Sphere

The product stores access control list files in a directory or other container that is accessible to actors outside of the intended control sphere.