CRITICAL🇵🇱 Wersja polska

CVE-2022-35869

CVSS 9.8v3.1pub. 2022-07-25upd. 2024-11-21

This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within com.inductiveautomation.ignition.gateway.web.pages. The issue results from the lack of proper authentication prior to access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-17211.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Inductiveautomation Ignition

    APP
    Inductiveautomation
    8.1.15
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2023-39475CRITICAL9.8PL ✓same product

RCE przez deserializację w Inductive Automation Ignition (ParameterVersionJavaSerializationCodec)

CVE-2023-39476CRITICAL9.8PL ✓same product

Inductive Automation Ignition — RCE przez deserialization w JavaSerializationCodec

CVE-2023-38121CRITICAL9.0PL ✓same product

XSS do RCE w Inductive Automation Ignition OPC UA Quick Client

CVE-2022-35890CRITICAL9.8PL ✓same product

Przejęcie sesji w Inductive Automation Ignition przez słabe ID sesji

CVE-2023-38122HIGH7.2same product

Inductive Automation Ignition OPC UA Quick Client Permissive Cross-domain Policy Remote Code Execution Vulnera...