PT-2022-22979 · Inductive Automation · Inductive Automation Ignition

S_N_T

·

Published

2022-07-15

·

Updated

2022-08-03

·

CVE-2022-35869

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Inductive Automation Ignition version 8.1.15 (b2022030114)
Description This issue allows remote attackers to bypass authentication on affected installations. The flaw exists within com.inductiveautomation.ignition.gateway.web.pages due to the lack of proper authentication prior to access to functionality. An attacker can leverage this to bypass authentication on the system.
Recommendations For version 8.1.15 (b2022030114), consider restricting access to the com.inductiveautomation.ignition.gateway.web.pages functionality until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2022-35869
ZDI-22-1016

Affected Products

Inductive Automation Ignition