Ecava develops industrial automation and SCADA integration software, with its vulnerability footprint concentrated in the Integraxor platform, a data acquisition and supervisory control tool deployed in process-monitoring and critical-infrastructure environments. The vendor's disclosures cluster around input-handling and access-control weaknesses, including SQL injection, path traversal, improper buffer management, and sensitive information exposure, reflecting the parsing demands and privileged role of middleware connecting operational technology networks. A meaningful share of the vendor's vulnerabilities reach serious severity, and a moderate tendency toward public exploit availability characterizes this product line. Defenders operating Integraxor instances should prioritize patching and restrict network exposure of the platform; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ecava over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4597HIGH Stack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraXor Human-Machine Interface (HMI) before 3.5.3900.10 allows r | Dec 23, 2010 | 10.0 | 49 | NO | YES |
CVE-2010-4598MEDIUM Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file_name parameter in an ope | Dec 23, 2010 | 5.0 | 40 | NO | YES |
CVE-2016-8341CRITICAL An issue was discovered in Ecava IntegraXor Version 5.0.413.0. The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. If the queries are not sanitized | Feb 13, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-6050CRITICAL A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which may allow for an unauthenticate | Jun 21, 2017 | 9.8 | 31 | NO | NO |
CVE-2012-0246HIGH Directory traversal vulnerability in an unspecified ActiveX control in Ecava IntegraXor before 3.71.4200 allows remote attackers to execute arbitrary code via vectors involving an | Apr 2, 2012 | 9.3 | 29 | NO | NO |
CVE-2012-4700HIGH Multiple buffer overflows in an ActiveX control in PE3DO32A.ocx in IntegraXor SCADA Server 4.00 build 4250.0 and earlier allow remote attackers to execute arbitrary code via a craf | Feb 8, 2013 | 9.3 | 28 | NO | NO |
CVE-2014-2375HIGH Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read or write to arbitrary files, and obtain sensitive informatio | Sep 15, 2014 | 9.0 | 23 | NO | NO |
CVE-2014-0753HIGH Stack-based buffer overflow in the SCADA server in Ecava IntegraXor before 4.1.4390 allows remote attackers to cause a denial of service (system crash) by triggering access to DLL | Jan 21, 2014 | 7.8 | 23 | NO | NO |
CVE-2016-2306HIGH The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing the network. | Apr 22, 2016 | 7.5 | 22 | NO | NO |
CVE-2016-2299HIGH SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Apr 22, 2016 | 7.3 | 22 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ecava.
Media articles that mention a CVE ID that affects a product developed by Ecava — matched by CVE ID, not by vendor name.