CVE-2022-36126Incorrect Authorization in Ignition

Severity
7.2HIGHNVD
EPSS
3.9%
top 11.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 16
Latest updateJul 17

Description

An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. The ScriptInvoke function allows remote attackers to execute arbitrary code by supplying a Python script.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages1 packages

NVDinductiveautomation/ignition8.0.18.1.17+1

🔴Vulnerability Details

2
GHSA
GHSA-p63h-vpc2-p933: An issue was discovered in Inductive Automation Ignition before 72022-07-17
CVEList
CVE-2022-36126: An issue was discovered in Inductive Automation Ignition before 72022-07-16
CVE-2022-36126 — Incorrect Authorization in Ignition | cvebase