B
今週中
Ecava IntegraXor IGX 16.0.701.10 において、認証なしで任意のファイルを書き込み、リモートコード実行 (RCE) が可能な脆弱性
📌 一言でいうと
SCADA HMI製品">Ecava IntegraXor IGX 16.0.701.10 において、認証なしで任意のファイルを書き込み、リモートコード実行 (RCE) が可能な脆弱性が報告されました。攻撃者は /FileUpload エンドポイントを悪用して悪意のある設定ファイルを配置し、DX Manager の起動時にそのファイルが実行される仕組みを利用します。この脆弱性は Windows プラットフォーム上の SCADA HMI サーバーに影響します。
🔍該当判定
- 製品名『Ecava IntegraXor IGX』を導入している
- 製造現場などのOT(制御系)ネットワークで、上記製品のWeb HMIサーバーを利用している
- 上記製品のバージョンが『16.0.701.10』である
上記いずれにも該当しない → 静観でOK
✅該当時の対応
ベンダーから提供される最新のセキュリティパッチを適用してください。また、管理インターフェースへのアクセス制限(ネットワーク分離やファイアウォールによる制限)を検討してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Ecava IntegraXor IGX RCE脆弱性への対応について
お疲れさまです。Ecava IntegraXor IGX に関する深刻な脆弱性の情報共有です。
■ 概要
Ecava IntegraXor IGX 16.0.701.10 において、認証不要で任意のファイルを書き込み、OSコマンドを実行できる脆弱性が発見されました。攻撃者は /FileUpload エンドポイントを悪用して悪意のある JSON ファイルを配置し、システム起動時にコードを実行させることが可能です。
■ 影響範囲
- 対象製品: Ecava IntegraXor IGX
- 対象バージョン: 16.0.701.10
- プラットフォーム: Windows
■ 対応手順
1. 該当製品のバージョンを確認し、最新の修正パッチが提供されているかベンダーに確認してください。
2. 修正パッチを適用してください。
3. 暫定対応として、DX Web HMI サーバー (デフォルトポート 8081) への外部からのアクセスを制限してください。
■ 参考情報
- Exploit-DB EDB-ID: 52688
対応優先度: 高
対応期限: 速やかに
お疲れさまです。Ecava IntegraXor IGX に関する深刻な脆弱性の情報共有です。
■ 概要
Ecava IntegraXor IGX 16.0.701.10 において、認証不要で任意のファイルを書き込み、OSコマンドを実行できる脆弱性が発見されました。攻撃者は /FileUpload エンドポイントを悪用して悪意のある JSON ファイルを配置し、システム起動時にコードを実行させることが可能です。
■ 影響範囲
- 対象製品: Ecava IntegraXor IGX
- 対象バージョン: 16.0.701.10
- プラットフォーム: Windows
■ 対応手順
1. 該当製品のバージョンを確認し、最新の修正パッチが提供されているかベンダーに確認してください。
2. 修正パッチを適用してください。
3. 暫定対応として、DX Web HMI サーバー (デフォルトポート 8081) への外部からのアクセスを制限してください。
■ 参考情報
- Exploit-DB EDB-ID: 52688
対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] RCE Vulnerability in Ecava IntegraXor IGX
Dear IT/Security Team,
We are sharing information regarding a critical vulnerability in Ecava IntegraXor IGX.
■ Overview
An unauthenticated Remote Code Execution (RCE) vulnerability has been identified in Ecava IntegraXor IGX 16.0.701.10. Attackers can exploit the /FileUpload endpoint to write arbitrary files to the system. By uploading a malicious JSON configuration file, the attacker can execute arbitrary commands via cmd.exe when the DX Manager orchestrator starts.
■ Scope
- Product: Ecava IntegraXor IGX
- Version: 16.0.701.10
- Platform: Windows
■ Mitigation Steps
1. Verify the installed version of Ecava IntegraXor IGX.
2. Apply the latest security patches provided by the vendor.
3. As a temporary measure, restrict network access to the DX Web HMI server (default port 8081) to trusted sources only.
■ Reference
- Exploit-DB EDB-ID: 52688
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing information regarding a critical vulnerability in Ecava IntegraXor IGX.
■ Overview
An unauthenticated Remote Code Execution (RCE) vulnerability has been identified in Ecava IntegraXor IGX 16.0.701.10. Attackers can exploit the /FileUpload endpoint to write arbitrary files to the system. By uploading a malicious JSON configuration file, the attacker can execute arbitrary commands via cmd.exe when the DX Manager orchestrator starts.
■ Scope
- Product: Ecava IntegraXor IGX
- Version: 16.0.701.10
- Platform: Windows
■ Mitigation Steps
1. Verify the installed version of Ecava IntegraXor IGX.
2. Apply the latest security patches provided by the vendor.
3. As a temporary measure, restrict network access to the DX Web HMI server (default port 8081) to trusted sources only.
■ Reference
- Exploit-DB EDB-ID: 52688
Priority: High
Deadline: Immediate