Remote Code Execution (RCE) Vulnerability Discovered in Ecava ntegraXor IGX 16.0.701.10
What Happened — An unauthenticated remote code execution flaw has been published for Ecava ntegraXor IGX version 16.0.701.10. The vulnerability allows an attacker to inject and execute arbitrary commands on the target system without valid credentials. The exploit is publicly available on Exploit‑DB (ID 52688).
Why It Matters for Trust & Control Assurance —
- This is exactly the scenario a continuous vulnerability‑management program is built to detect, prioritize, and remediate before an attacker can exploit it.
- Demonstrating timely patching and evidence of remediation satisfies a core control objective around “maintain up‑to‑date software and remediate known weaknesses,” which maps to many frameworks (e.g., NIST CSF 2.0).
- Verisq’s Control Mapping capability can automatically align the vulnerability to the relevant VCF control, collect remediation evidence, and feed it into your audit‑readiness dashboard.
Who Is Affected — Manufacturers and other industrial operators that deploy Ecava ntegraXor IGX for SCADA/automation.
Recommended Actions —
- Verify whether any assets run IGX 16.0.701.10 and inventory them in your asset database.
- Apply Ecava’s patch or upgrade to a non‑vulnerable version immediately; document the change as control evidence.
- Update your vulnerability‑management workflow to include this CVE‑like entry and map it to the “patch management” control in your trust‑center.
Source: Exploit‑DB 52688
Technical Notes — The flaw is a remote code execution (RCE) triggered via a crafted network request to the IGX service. No CVE identifier has been assigned yet, but the exploit demonstrates full system compromise. Source: Exploit‑DB 52688