[0day-rubbish] Ecava IntegraXor IGX 16.0.701.10 Unauthenticated /FileUpload write chained to the dxmanager cmd.exe sink (9.8)
Unauthenticated file upload in Ecava IntegraXor IGX 16.0.701.10 chains to cmd.exe for Administrator code execution.
0day Rubbish Research Team publicly disclosed an unauthenticated remote code execution flaw in Ecava IntegraXor IGX 16.0.701.10. An unauthenticated /FileUpload write is chained to the dxmanager cmd.exe sink (CWE-306), yielding arbitrary command execution as Administrator on the Web SCADA HMI host. The reported CVSS is 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The post says a full analysis and reproducible proof-of-concept were published; no CVE or observed exploitation is stated.
- Affects Ecava IntegraXor IGX 16.0.701.10 Web SCADA HMI.
- Unauthenticated /FileUpload write chains into the dxmanager cmd.exe sink.
- CVSS 9.8; command execution as Administrator; public reproducible PoC.
- No CVE id and no confirmed in-the-wild exploitation in the post.
Posted by disclosure via Fulldisclosure on Sep 22 0day Rubbish Research Team is publicly disclosing a vulnerability in Ecava IntegraXor IGX 16.0.701.10. Type: Unauthenticated /FileUpload write chained to the dxmanager cmd.exe sink (CWE-306) CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) Impact: arbitrary command execution as Administrator on a Web SCADA HMI host Authentication: unauthenticated Full technical analysis and a reproducible proof-of-concept:...
This source does not provide full text. Read it at seclists.org.