Lucene search

K
zdi@_s_n_t of @pentestltdZDI-22-1016
HistoryJul 15, 2022 - 12:00 a.m.

(Pwn2Own) Inductive Automation Ignition Authentication Bypass Vulnerability

2022-07-1500:00:00
@_s_n_t of @pentestltd
www.zerodayinitiative.com
18

0.023 Low

EPSS

Percentile

89.7%

This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition. Authentication is not required to exploit this vulnerability. The specific flaw exists within com.inductiveautomation.ignition.gateway.web.pages. The issue results from the lack of proper authentication prior to access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system.

0.023 Low

EPSS

Percentile

89.7%

Related for ZDI-22-1016