7.5
CVE-2014-0786
- EPSS 1.87%
- Veröffentlicht 01.05.2014 01:56:10
- Zuletzt bearbeitet 13.10.2025 23:15:34
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via SELECT statements that leverage the guest role.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ecava ≫ Integraxor Version <= 4.1.4390
Ecava ≫ Integraxor Version4.1
Ecava ≫ Integraxor Version4.1.4340
Ecava ≫ Integraxor Version4.1.4360
Ecava ≫ Integraxor Version4.1.4369
Ecava ≫ Integraxor Version4.1.4380
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.87% | 0.827 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
| ics-cert@hq.dhs.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.