VendorsInductive Automationignitionall versions
Vulnerabilities

Inductive Automation Ignition

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

35CVEs
CVE-2023-39475
Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
9.8EPSS 0.641
CVE-2022-35869
This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within com.inductiveautomation.ignition.gateway.web.pages. The issue results from the lack of proper authentication prior to access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-17211.
Published 2022-07-25 · Modified
9.8EPSS 0.603
CVE-2023-39476
Inductive Automation Ignition JavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
9.8EPSS 0.022
CVE-2022-35890
An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. Designer and Vision Client Session IDs are mishandled. An attacker can determine which session IDs were generated in the past and then hijack sessions assigned to these IDs via Randy.
Published 2022-07-15 · Modified
9.8EPSS 0.020
CVE-2022-1704
Inductive Automation Ignition
Published 2022-08-05 · Modified
9.8EPSS 0.010
CVE-2023-38121
Inductive Automation Ignition OPC UA Quick Client Cross-Site Scripting Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
9.0EPSS 0.012
CVE-2023-39473
Inductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.625
CVE-2023-38124
Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.596
CVE-2023-50223
Inductive Automation Ignition ExtendedDocumentCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.552
CVE-2023-50218
Inductive Automation Ignition ModuleInvoke Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.550
CVE-2022-35870
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within com.inductiveautomation.metro.impl. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-17265.
Published 2022-07-25 · Modified
8.8EPSS 0.433
CVE-2023-50233
Inductive Automation Ignition getJavaExecutable Directory Traversal Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.021
CVE-2023-50220
Inductive Automation Ignition Base64Element Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.018
CVE-2023-50219
Inductive Automation Ignition RunQuery Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.015
CVE-2023-50232
Inductive Automation Ignition getParams Argument Injection Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.014
CVE-2023-38123
Inductive Automation Ignition OPC UA Quick Client Missing Authentication for Critical Function Authentication Bypass Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.012
CVE-2023-50222
Inductive Automation Ignition ResponseParser Notification Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.011
CVE-2023-50221
Inductive Automation Ignition ResponseParser SerializedResponse Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.011
CVE-2022-1264
Inductive Automation Ignition
Published 2022-07-20 · Modified
8.8EPSS 0.009
CVE-2023-39474
Inductive Automation Ignition downloadLaunchClientJar Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.006
CVE-2022-35871
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within the authenticateAdSso method. The issue results from the lack of authentication prior to allowing the execution of python code. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-17206.
Published 2022-07-25 · Modified
8.1EPSS 0.392
CVE-2022-35873
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of ZIP files. Crafted data in a ZIP file can cause the application to execute arbitrary Python scripts. The user interface fails to provide sufficient indication of the hazard. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-16949.
Published 2022-07-25 · Modified
7.8EPSS 0.007
CVE-2022-35872
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ZIP files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-17115.
Published 2022-07-25 · Modified
7.8EPSS 0.007
CVE-2023-39477
Inductive Automation Ignition ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability
Published 2024-05-03 · Analyzed
7.5EPSS 0.015
CVE-2022-36126
An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. The ScriptInvoke function allows remote attackers to execute arbitrary code by supplying a Python script.
Published 2022-07-16 · Modified
7.2EPSS 0.026
CVE-2023-38122
Inductive Automation Ignition OPC UA Quick Client Permissive Cross-domain Policy Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.2EPSS 0.019
CVE-2025-13913
Inductive Automation Ignition Software Deserialization of Untrusted Data
Published 2026-03-12 · Analyzed
6.8EPSS 0.003
CVE-2023-39472
Inductive Automation Ignition SimpleXMLReader XML External Entity Processing Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
6.5EPSS 0.013
CVE-2015-0993
Inductive Automation Ignition 7.7.2 does not terminate a session upon a logout action, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.
Published 2015-04-03 · Modified
6.4EPSS 0.023
CVE-2020-14479
ICSA-20-147-01 Inductive Automation Ignition (Update B)
Published 2022-04-01 · Modified
5.3EPSS 0.009
CVE-2015-0991
Inductive Automation Ignition 7.7.2 allows remote attackers to obtain sensitive information by reading an error message about an unhandled exception, as demonstrated by pathname information.
Published 2015-04-03 · Modified
5.0EPSS 0.013
CVE-2015-0995
Inductive Automation Ignition 7.7.2 uses MD5 password hashes, which makes it easier for context-dependent attackers to obtain access via a brute-force attack.
Published 2015-04-03 · Modified
5.0EPSS 0.011
CVE-2015-0976
Cross-site scripting (XSS) vulnerability in Inductive Automation Ignition 7.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2015-04-03 · Modified
4.3EPSS 0.011
CVE-2015-0994
Inductive Automation Ignition 7.7.2 allows remote authenticated users to bypass a brute-force protection mechanism by using different session ID values in a series of HTTP requests.
Published 2015-04-03 · Modified
4.0EPSS 0.013
CVE-2015-0992
Inductive Automation Ignition 7.7.2 stores cleartext OPC Server credentials, which allows local users to obtain sensitive information via unspecified vectors.
Published 2015-04-03 · Modified
2.1EPSS 0.003