« Volver al listado

CVE-2014-0786

Estado: ModificadaMedia (5)—

Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via SELECT statements that leverage the guest role.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-0786",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Secondary",
        "source": "ics-cert@hq.dhs.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "Ecava",
          "product": "IntegraXor",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "4.1.4410",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2014-05-01T01:56:10.490",
  "references": [
    {
      "url": "http://www.integraxor.com/blog/category/security/vulnerability-note/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "http://www.integraxor.com/blog/category/security/vulnerability-note/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "http://www.integraxor.com/blog/category/security/vulnerability-note/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "http://www.integraxor.com/blog/category/security/vulnerability-note/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-14-091-01",
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-14-224-01",
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "http://ics-cert.us-cert.gov/advisories/ICSA-14-091-01",
      "tags": [
        "Patch",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.integraxor.com/blog/category/security/vulnerability-note/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ics-cert@hq.dhs.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via SELECT statements that leverage the guest role."
    },
    {
      "lang": "es",
      "value": "Ecava IntegraXor anterior a 4.1.4393 permite a atacantes remotos leer credenciales en texto plano para cuentas administrativas a través de declaraciones SELECT que aprovechan el rol de invitado."
    }
  ],
  "lastModified": "2026-06-17T00:03:38.297",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ecava:integraxor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40E2214C-80FC-4973-BF67-1ECFC1C5D303",
              "versionEndIncluding": "4.1.4390"
            },
            {
              "criteria": "cpe:2.3:a:ecava:integraxor:4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C254168-384E-4B0A-BB22-445D7281FAC8"
            },
            {
              "criteria": "cpe:2.3:a:ecava:integraxor:4.1.4340:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1223B72-A344-450E-8E10-1B704DF894BB"
            },
            {
              "criteria": "cpe:2.3:a:ecava:integraxor:4.1.4360:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0319EBA-C39F-4A3D-AF40-7A90FA016696"
            },
            {
              "criteria": "cpe:2.3:a:ecava:integraxor:4.1.4369:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5EA3EDD6-3459-4916-B184-271A43FAC10A"
            },
            {
              "criteria": "cpe:2.3:a:ecava:integraxor:4.1.4380:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C4C3DBE0-50B6-4A39-9FA5-878951AD855E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}