Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via SELECT statements that leverage the guest role.
https://www.cisa.gov/news-events/ics-advisories/icsa-14-224-01
https://www.cisa.gov/news-events/ics-advisories/icsa-14-091-01
http://www.integraxor.com/blog/category/security/vulnerability-note/