Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ecava

First CVE: Dec 23, 2010Active for: 16 yearsTotal CVEs: 26
46.4
VTI Score
High

Ecava develops industrial automation and SCADA integration software, with its vulnerability footprint concentrated in the Integraxor platform, a data acquisition and supervisory control tool deployed in process-monitoring and critical-infrastructure environments. The vendor's disclosures cluster around input-handling and access-control weaknesses, including SQL injection, path traversal, improper buffer management, and sensitive information exposure, reflecting the parsing demands and privileged role of middleware connecting operational technology networks. A meaningful share of the vendor's vulnerabilities reach serious severity, and a moderate tendency toward public exploit availability characterizes this product line. Defenders operating Integraxor instances should prioritize patching and restrict network exposure of the platform; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ecava over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 23, 2010
15 years ago
Most Recent CVE
Dec 20, 2017
3,138 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-4597HIGH
Stack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraXor Human-Machine Interface (HMI) before 3.5.3900.10 allows r
Dec 23, 201010.049NOYES
CVE-2010-4598MEDIUM
Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file_name parameter in an ope
Dec 23, 20105.040NOYES
CVE-2016-8341CRITICAL
An issue was discovered in Ecava IntegraXor Version 5.0.413.0. The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. If the queries are not sanitized
Feb 13, 20179.832NONO
CVE-2017-6050CRITICAL
A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which may allow for an unauthenticate
Jun 21, 20179.831NONO
CVE-2012-0246HIGH
Directory traversal vulnerability in an unspecified ActiveX control in Ecava IntegraXor before 3.71.4200 allows remote attackers to execute arbitrary code via vectors involving an
Apr 2, 20129.329NONO
CVE-2012-4700HIGH
Multiple buffer overflows in an ActiveX control in PE3DO32A.ocx in IntegraXor SCADA Server 4.00 build 4250.0 and earlier allow remote attackers to execute arbitrary code via a craf
Feb 8, 20139.328NONO
CVE-2014-2375HIGH
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read or write to arbitrary files, and obtain sensitive informatio
Sep 15, 20149.023NONO
CVE-2014-0753HIGH
Stack-based buffer overflow in the SCADA server in Ecava IntegraXor before 4.1.4390 allows remote attackers to cause a denial of service (system crash) by triggering access to DLL
Jan 21, 20147.823NONO
CVE-2016-2306HIGH
The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing the network.
Apr 22, 20167.522NONO
CVE-2016-2299HIGH
SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Apr 22, 20167.322NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
58%
35%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (46.2%)
Unknown14 (53.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (46.2%)
High0 (0.0%)
Unknown14 (53.8%)
User Interaction
None10 (38.5%)
Unknown14 (53.8%)
Required2 (7.7%)
Privileges Required
Low1 (3.8%)
High0 (0.0%)
None11 (42.3%)
Unknown14 (53.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
7.7% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ecava.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ecava — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ecava's Products

View all 3 CNAs →

Top CWEs