Posted by disclosure via Fulldisclosure on Sep 22 0day Rubbish Research Team is publicly disclosing a vulnerability in Ecava IntegraXor IGX 16.0.701.10. Type: Unauthenticated /FileUpload write chained to the dxmanager cmd.exe sink (CWE-306) CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) Impact: arbitrary command execution as Administrator on a Web SCADA HMI host Authentication: unauthenticated Full technical analysis and a reproducible proof-of-concept:...

Read the full article at Full Disclosure →