Inductive Automation Ignition OPC UA Quick Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the id parameter provided to the Inductive Automation Ignition web interface. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-20355.
The vulnerability results from insufficient validation of user-supplied data in the 'id' parameter of the Ignition OPC UA Quick Client web interface. An attacker can inject arbitrary JavaScript code (XSS), which will be executed in the victim's browser context. By leveraging this technique, the attacker can escalate the attack to achieve code execution at the operating system level (RCE). For the exploit to work, the victim must visit a malicious website or open a malicious file.
An attacker can execute arbitrary code in the context of the SYSTEM account on the targeted installation, resulting in complete system compromise, including access to sensitive data, configuration modification, and potential disruption of industrial processes handled by Ignition.
Apply patches available from the vendor according to the references. Inductive Automation has published patch information related to Pwn2Own participation — details are available on the vendor's website and in the ZDI-23-1012 advisory.
Inductive Automation Ignition installations — specific versions indicated in the vendor's references and in the Zero Day Initiative advisory (ZDI-23-1012)
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HInductiveautomation Ignition
APPInductiveautomation< 8.1.26
Related vulnerabilities
Inductive Automation Ignition — RCE przez deserialization w JavaSerializationCodec
RCE przez deserializację w Inductive Automation Ignition (ParameterVersionJavaSerializationCodec)
Pominięcie uwierzytelnienia w Inductive Automation Ignition (Auth Bypass)
Przejęcie sesji w Inductive Automation Ignition przez słabe ID sesji
Inductive Automation Ignition OPC UA Quick Client Permissive Cross-domain Policy Remote Code Execution Vulnera...