The SCADA server in Ecava IntegraXor before 4.1.4369 allows remote attackers to read arbitrary project backup files via a crafted URL.
Solution:
The product stores access control list files in a directory or other container that is accessible to actors outside of the intended control sphere.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.integraxor.com/blog/category/security/vulnerability-note/ | patch vendor advisory |
https://www.cisa.gov/news-events/ics-advisories/icsa-14-008-01 | |
http://ics-cert.us-cert.gov/advisories/ICSA-14-008-01 | patch us government resource |