📦 Ignition

by Inductiveautomation

🔍 What is Ignition?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-39475

CRITICAL CVSS 9.8 May 3, 2024

This vulnerability allows unauthenticated remote attackers to execute arbitrary code with SYSTEM privileges on Inductive Automation Ignition installations. The flaw exists in the ParameterVersionJavaS...

CVE-2023-38121

CRITICAL CVSS 9.0 May 3, 2024

This is a cross-site scripting (XSS) vulnerability in Inductive Automation Ignition's OPC UA Quick Client web interface that allows remote code execution. Attackers can inject malicious scripts via th...

CVE-2022-35869

CRITICAL CVSS 9.8 Jul 25, 2022

CVE-2022-35869 is an authentication bypass vulnerability in Inductive Automation Ignition that allows remote attackers to access protected functionality without credentials. This affects Ignition 8.1....

CVE-2022-35890

CRITICAL CVSS 9.8 Jul 15, 2022

This vulnerability allows attackers to predict previously generated session IDs in Inductive Automation Ignition, enabling session hijacking. Attackers can take over active user sessions in Designer a...

CVE-2023-50233

HIGH CVSS 8.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code on Inductive Automation Ignition installations by exploiting a directory traversal flaw in the getJavaExecutable method. Attackers ...

CVE-2023-50221

HIGH CVSS 8.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code on Inductive Automation Ignition installations by exploiting insecure deserialization in the ResponseParser. Attackers can compromi...

CVE-2023-50223

HIGH CVSS 8.8 May 3, 2024

This vulnerability in Inductive Automation Ignition allows authenticated remote attackers to execute arbitrary code with SYSTEM privileges by exploiting insecure deserialization in the ExtendedDocumen...

CVE-2023-50219

HIGH CVSS 8.8 May 3, 2024

This vulnerability in Inductive Automation Ignition allows authenticated remote attackers to execute arbitrary code with SYSTEM privileges by exploiting insecure deserialization in the RunQuery class....

CVE-2023-39473

HIGH CVSS 8.8 May 3, 2024

This vulnerability allows authenticated remote attackers to execute arbitrary code on Inductive Automation Ignition systems by exploiting insecure deserialization in the AbstractGatewayFunction class....

CVE-2023-39477

HIGH CVSS 7.5 May 3, 2024

This vulnerability allows unauthenticated remote attackers to cause denial-of-service by sending excessive OPC UA ConditionRefresh requests to Inductive Automation Ignition servers, consuming all avai...

CVE-2023-38124

HIGH CVSS 8.8 May 3, 2024

This vulnerability in Inductive Automation Ignition allows authenticated remote attackers to execute arbitrary code with SYSTEM privileges by exploiting an exposed dangerous function in the OPC UA Qui...

CVE-2023-38123

HIGH CVSS 8.8 May 3, 2024

This vulnerability allows remote attackers to bypass authentication in Inductive Automation Ignition OPC UA Quick Client by exploiting missing authentication on password change functionality. Attacker...

CVE-2022-35873

HIGH CVSS 7.8 Jul 25, 2022

This vulnerability allows remote attackers to execute arbitrary code on Inductive Automation Ignition installations by tricking users into opening malicious ZIP files. The flaw in ZIP file processing ...

CVE-2022-35871

HIGH CVSS 7.8 Jul 25, 2022

This vulnerability allows unauthenticated remote attackers to execute arbitrary Python code with SYSTEM privileges on Inductive Automation Ignition installations. The flaw exists in the authenticateAd...