CVE-2014-2375
CVE-2014-2375 is a high-severity vulnerability in Ecava Integraxor with a CVSS 2.0 base score of 8.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-73.
Key facts
- Severity: High (CVSS 2.0 base score 8.3)
- EPSS exploit prediction: 2% (82nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-73
- Affected product: Ecava Integraxor
- Published:
- Last modified:
Description
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read or write to arbitrary files, and obtain sensitive information or cause a denial of service (disk consumption), via the CSV export feature.
Frequently asked questions
- What is CVE-2014-2375?
- Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read or write to arbitrary files, and obtain sensitive information or cause a denial of service (disk consumption), via the CSV export feature.
- How severe is CVE-2014-2375?
- CVE-2014-2375 has a CVSS 2.0 base score of 8.3, rated high severity.
- Is CVE-2014-2375 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (82nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2014-2375?
- CVE-2014-2375 primarily affects Ecava Integraxor. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2014-2375?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2014-2375 published?
- CVE-2014-2375 was published on 2014-09-15 and last updated on 2026-06-17.
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-14-224-01
- https://ics-cert.us-cert.gov/advisories/ICSA-14-224-01
Affected products (2)
- cpe:2.3:a:ecava:integraxor:*:*:*:*:*:*:*:*
- cpe:2.3:a:ecava:integraxor:*:beta:*:*:*:*:*:*
More vulnerabilities in Ecava Integraxor
- CVE-2010-4597 — Critical (CVSS 10.0): Stack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava…
- CVE-2017-6050 — Critical (CVSS 9.8): A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to…
- CVE-2016-8341 — Critical (CVSS 9.8): An issue was discovered in Ecava IntegraXor Version 5.0.413.0. The Ecava IntegraXor web server has parameters that are…
- CVE-2012-4700 — Critical (CVSS 9.3): Multiple buffer overflows in an ActiveX control in PE3DO32A.ocx in IntegraXor SCADA Server 4.00 build 4250.0 and…
- CVE-2012-0246 — Critical (CVSS 9.3): Directory traversal vulnerability in an unspecified ActiveX control in Ecava IntegraXor before 3.71.4200 allows remote…
- CVE-2014-0753 — High (CVSS 7.8): Stack-based buffer overflow in the SCADA server in Ecava IntegraXor before 4.1.4390 allows remote attackers to cause a…
All CVEs affecting Ecava Integraxor →
Other CWE-73 vulnerabilities
- CVE-2026-20358 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team…
- CVE-2026-50148 — Critical (CVSS 10.0): Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24,…
- CVE-2025-71338 — Critical (CVSS 10.0): Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows…
- CVE-2026-39907 — Critical (CVSS 10.0): Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on…
- CVE-2026-27211 — Critical (CVSS 10.0): Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Versions 34.0 through 50.0 arevulnerable to…
- CVE-2026-63343 — Critical (CVSS 9.9): Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a…