Integraxor

Vendor:

First CVE: Dec 23, 2010 · Active for 15 years

26
Total CVEs
More Total CVEs than 95% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Integraxor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 23, 2010
15 years ago
Most Recent CVE
Dec 20, 2017
3,139 days ago

CVE Severity & Scoring

Integraxor26 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (46.2%)
Unknown14 (53.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (46.2%)
High0 (0.0%)
Unknown14 (53.8%)
User Interaction
None10 (38.5%)
Unknown14 (53.8%)
Required2 (7.7%)
Privileges Required
Low1 (3.8%)
High0 (0.0%)
None11 (42.3%)
Unknown14 (53.8%)

Top CVEs

Signals from CVEs in this product scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraXor Human-Machine Interface (HMI) before 3.5.3900.10 allows r
Dec 23, 201010.049NOYES
Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file_name parameter in an ope
Dec 23, 20105.040NOYES
An issue was discovered in Ecava IntegraXor Version 5.0.413.0. The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. If the queries are not sanitized
Feb 13, 20179.832NONO
A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which may allow for an unauthenticate
Jun 21, 20179.831NONO
Directory traversal vulnerability in an unspecified ActiveX control in Ecava IntegraXor before 3.71.4200 allows remote attackers to execute arbitrary code via vectors involving an
Apr 2, 20129.329NONO
Multiple buffer overflows in an ActiveX control in PE3DO32A.ocx in IntegraXor SCADA Server 4.00 build 4250.0 and earlier allow remote attackers to execute arbitrary code via a craf
Feb 8, 20139.328NONO
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read or write to arbitrary files, and obtain sensitive informatio
Sep 15, 20149.023NONO
Stack-based buffer overflow in the SCADA server in Ecava IntegraXor before 4.1.4390 allows remote attackers to cause a denial of service (system crash) by triggering access to DLL
Jan 21, 20147.823NONO
The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing the network.
Apr 22, 20167.522NONO
SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Apr 22, 20167.322NONO

Exploit Exposure

Signals from CVEs in this product scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
7.7% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (26 CVEs).

Media Mentions

Signals from CVEs in this product scope (26 CVEs).

Top CNAs Publishing CVEs For Integraxor

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.0.413.019.81.7%00
4.1.438015.02.6%00
4.1.436926.42.6%00
4.1.436026.42.6%00
4.1.434015.02.6%00
4.135.92.3%00
4.0026.42.1%00
3.7237.42.6%00
3.71.420026.42.1%00
3.7137.42.6%00
3.6.4000.056.72.4%00
3.60.406126.42.1%00
3.6026.83.6%00
3.5.3900.556.37.6%01
3.5.3900.1056.37.6%01