CVE ID | CVE-2022-35869 |
CVSS SCORE | 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
AFFECTED VENDORS |
Inductive Automation |
AFFECTED PRODUCTS |
Ignition |
VULNERABILITY DETAILS |
This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition. Authentication is not required to exploit this vulnerability. The specific flaw exists within com.inductiveautomation.ignition.gateway.web.pages. The issue results from the lack of proper authentication prior to access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. |
ADDITIONAL DETAILS |
Inductive Automation has issued an update to correct this vulnerability. More details can be found at:
https://support.inductiveautomation.com/hc/en-us/articles/7625759776653-Regarding-Pwn2Own-2022-Vulnerabilities |
DISCLOSURE TIMELINE |
|
CREDIT | @_s_n_t of @pentestltd |