CVE-2022-35871Missing Authentication for Critical Function in Automation Ignition

Severity
7.8HIGHNVD
EPSS
42.0%
top 2.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 25
Latest updateJul 26

Description

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within the authenticateAdSso method. The issue results from the lack of authentication prior to allowing the execution of python code. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-17206.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5inductive_automation/ignition8.1.15 (b2022030114)

🔴Vulnerability Details

3
GHSA
GHSA-r5vj-595h-w86q: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 82022-07-26
CVEList
CVE-2022-35871: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 82022-07-25
VulnCheck
inductiveautomation Ignition Missing Authentication for Critical Function2022
CVE-2022-35871 — Automation Ignition vulnerability | cvebase