CRITICAL🇵🇱 Wersja polska

CVE-2023-38121

CVSS 9.0v3.1pub. 2024-05-03upd. 2025-03-12

Inductive Automation Ignition OPC UA Quick Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the id parameter provided to the Inductive Automation Ignition web interface. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-20355.

🤖 AI Analysis
How it works

The vulnerability results from insufficient validation of user-supplied data in the 'id' parameter of the Ignition OPC UA Quick Client web interface. An attacker can inject arbitrary JavaScript code (XSS), which will be executed in the victim's browser context. By leveraging this technique, the attacker can escalate the attack to achieve code execution at the operating system level (RCE). For the exploit to work, the victim must visit a malicious website or open a malicious file.

Impact

An attacker can execute arbitrary code in the context of the SYSTEM account on the targeted installation, resulting in complete system compromise, including access to sensitive data, configuration modification, and potential disruption of industrial processes handled by Ignition.

Mitigation & patch

Apply patches available from the vendor according to the references. Inductive Automation has published patch information related to Pwn2Own participation — details are available on the vendor's website and in the ZDI-23-1012 advisory.

Who is affected

Inductive Automation Ignition installations — specific versions indicated in the vendor's references and in the Zero Day Initiative advisory (ZDI-23-1012)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Inductiveautomation Ignition

    APP
    Inductiveautomation
    < 8.1.26
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEXSS
CWE
References

Related vulnerabilities

CVE-2023-39476CRITICAL9.8PL ✓same product

Inductive Automation Ignition — RCE przez deserialization w JavaSerializationCodec

CVE-2023-39475CRITICAL9.8PL ✓same product

RCE przez deserializację w Inductive Automation Ignition (ParameterVersionJavaSerializationCodec)

CVE-2022-35869CRITICAL9.8PL ✓same product

Pominięcie uwierzytelnienia w Inductive Automation Ignition (Auth Bypass)

CVE-2022-35890CRITICAL9.8PL ✓same product

Przejęcie sesji w Inductive Automation Ignition przez słabe ID sesji

CVE-2023-38122HIGH7.2same product

Inductive Automation Ignition OPC UA Quick Client Permissive Cross-domain Policy Remote Code Execution Vulnera...