CVE-2014-0753
high
CVSS v3
—
CVSS v2
7.8
VIR risk
7.8
Description
Stack-based buffer overflow in the SCADA server in Ecava IntegraXor before 4.1.4390 allows remote attackers to cause a denial of service (system crash) by triggering access to DLL code located in the IntegraXor directory.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: ics-cert@hq.dhs.gov — http://www.integraxor.com/blog/buffer-overflow-vulnerability-note/
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ecava | integraxor | {"endIncluding":"4.1.4380"} | |
| ecava | integraxor | 3.5.3900.5 | |
| ecava | integraxor | 3.5.3900.10 | |
| ecava | integraxor | 3.6.4000.0 | |
| ecava | integraxor | 3.60.4061 | |
| ecava | integraxor | 3.71 | |
| ecava | integraxor | 3.71.4200 | |
| ecava | integraxor | 3.72 | |
| ecava | integraxor | 4.00 | |
| ecava | integraxor | 4.1 | |
| ecava | integraxor | 4.1.4360 | |
| ecava | integraxor | 4.1.4369 | |
References
CWEs
CWE-121 CWE-119
Verify integrity in audit chain (admin only). AS-IS.