Ecava IntegraXor < 4.2.4488 Privilege Escalation

Medium Nessus Plugin ID 82698


A SCADA application installed on the remote Windows host is affected by a privilege escalation vulnerability.


The version of Ecava IntegraXor SCADA Server installed on the remote Windows host is prior to version 4.2.4488. It is, therefore, affected by a privilege escalation vulnerability due to using an insecure path when loading DLL files. A local attacker with administrative access to the default installation location can exploit this flaw to plant a malicious DLL file containing code that can then be run with the privileges of the application.


Upgrade to version 4.2.4488 or later.

See Also

Plugin Details

Severity: Medium

ID: 82698

File Name: scada_app_ecava_integraxor_4_2_4488.nbin

Version: $Revision: 1.22 $

Type: local

Family: SCADA

Published: 2015/04/10

Modified: 2018/01/29

Dependencies: 53548

Risk Information

Risk Factor: Medium


Base Score: 4.4

Vector: CVSS2#AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/a:ecava:integraxor

Required KB Items: installed_sw/Ecava IntegraXor

Patch Publication Date: 2015/04/01

Vulnerability Publication Date: 2015/03/31

Reference Information

CVE: CVE-2015-0990

BID: 73472

OSVDB: 120109

ICSA: 15-090-02