🔥 この記事の詳細
2026-10-01 更新
B
今週中

Ecava IntegraXor IGX 16.0.701.10 において、認証なしで任意のファイルを書き込み、リモートコード実行 (RCE) が可能な脆弱性

脆弱性🌐 英語ソース
📅 2026-10-01📰 exploit_db
📌 一言でいうと
SCADA HMI製品">Ecava IntegraXor IGX 16.0.701.10 において、認証なしで任意のファイルを書き込み、リモートコード実行 (RCE) が可能な脆弱性が報告されました。攻撃者は /FileUpload エンドポイントを悪用して悪意のある設定ファイルを配置し、DX Manager の起動時にそのファイルが実行される仕組みを利用します。この脆弱性は Windows プラットフォーム上の SCADA HMI サーバーに影響します。
🔍該当判定
  • 製品名『Ecava IntegraXor IGX』を導入している
  • 製造現場などのOT(制御系)ネットワークで、上記製品のWeb HMIサーバーを利用している
  • 上記製品のバージョンが『16.0.701.10』である
上記いずれにも該当しない → 静観でOK
✅該当時の対応
ベンダーから提供される最新のセキュリティパッチを適用してください。また、管理インターフェースへのアクセス制限(ネットワーク分離やファイアウォールによる制限)を検討してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Ecava IntegraXor IGX RCE脆弱性への対応について

お疲れさまです。Ecava IntegraXor IGX に関する深刻な脆弱性の情報共有です。

■ 概要
Ecava IntegraXor IGX 16.0.701.10 において、認証不要で任意のファイルを書き込み、OSコマンドを実行できる脆弱性が発見されました。攻撃者は /FileUpload エンドポイントを悪用して悪意のある JSON ファイルを配置し、システム起動時にコードを実行させることが可能です。

■ 影響範囲
- 対象製品: Ecava IntegraXor IGX
- 対象バージョン: 16.0.701.10
- プラットフォーム: Windows

■ 対応手順
1. 該当製品のバージョンを確認し、最新の修正パッチが提供されているかベンダーに確認してください。
2. 修正パッチを適用してください。
3. 暫定対応として、DX Web HMI サーバー (デフォルトポート 8081) への外部からのアクセスを制限してください。

■ 参考情報
- Exploit-DB EDB-ID: 52688

対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] RCE Vulnerability in Ecava IntegraXor IGX

Dear IT/Security Team,

We are sharing information regarding a critical vulnerability in Ecava IntegraXor IGX.

■ Overview
An unauthenticated Remote Code Execution (RCE) vulnerability has been identified in Ecava IntegraXor IGX 16.0.701.10. Attackers can exploit the /FileUpload endpoint to write arbitrary files to the system. By uploading a malicious JSON configuration file, the attacker can execute arbitrary commands via cmd.exe when the DX Manager orchestrator starts.

■ Scope
- Product: Ecava IntegraXor IGX
- Version: 16.0.701.10
- Platform: Windows

■ Mitigation Steps
1. Verify the installed version of Ecava IntegraXor IGX.
2. Apply the latest security patches provided by the vendor.
3. As a temporary measure, restrict network access to the DX Web HMI server (default port 8081) to trusted sources only.

■ Reference
- Exploit-DB EDB-ID: 52688

Priority: High
Deadline: Immediate