inductiveautomation kayıtları
inductiveautomation üreticisine ait 40 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %5
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-502 Deserialization of Untrusted Data14
- CWE-306 Missing Authentication for Critical Function4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-254 7PK - Security Features2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
40 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
58Planlayın | CVE-2023-39475İstismar yok | Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-502 | Kritik9,8 | — | %64,1 | 2 May 2024 |
57Planlayın | CVE-2022-35869İstismar yok | This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022inductiveautomation · ignition · CWE-288 | Kritik9,8 | — | %60,3 | 25 Tem 2022 |
54Planlayın | CVE-2023-39473İstismar yok | Inductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-502 | Yüksek8,8 | — | %62,5 | 2 May 2024 |
53Planlayın | CVE-2023-38124İstismar yok | Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-749 | Yüksek8,8 | — | %59,6 | 2 May 2024 |
52Planlayın | CVE-2023-50223İstismar yok | Inductive Automation Ignition ExtendedDocumentCodec Deserialization of Untrusted Data Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-502 | Yüksek8,8 | — | %55,2 | 2 May 2024 |
52Planlayın | CVE-2023-50218İstismar yok | Inductive Automation Ignition ModuleInvoke Deserialization of Untrusted Data Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-502 | Yüksek8,8 | — | %55,0 | 2 May 2024 |
44Planlayın | CVE-2022-35870İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202inductiveautomation · ignition · CWE-502 | Yüksek7,8 | — | %43,3 | 25 Tem 2022 |
43Planlayın | CVE-2022-35871İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202inductiveautomation · ignition · CWE-306 | Yüksek7,8 | — | %39,2 | 25 Tem 2022 |
40Planlayın | CVE-2023-39476İstismar yok | Inductive Automation Ignition JavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-502 | Kritik9,8 | — | %2,2 | 2 May 2024 |
40Planlayın | CVE-2022-35890İstismar yok | An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17.inductiveautomation · ignition · CWE-863 | Kritik9,8 | — | %2,0 | 15 Tem 2022 |
39İzleyin | CVE-2022-1704İstismar yok | Inductive Automation Ignitioninductiveautomation · ignition · CWE-611 | Kritik9,8 | — | %1,0 | 5 Ağu 2022 |
36İzleyin | CVE-2020-10644Silahlaştırılmış | The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 inductiveautomation · ignition gateway · CWE-502 | Yüksek7,5 | — | %20,2 | 9 Haz 2020 |
36İzleyin | CVE-2023-50233İstismar yok | Inductive Automation Ignition getJavaExecutable Directory Traversal Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-22 | Yüksek8,8 | — | %2,1 | 2 May 2024 |
36İzleyin | CVE-2023-50220İstismar yok | Inductive Automation Ignition Base64Element Deserialization of Untrusted Data Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-502 | Yüksek8,8 | — | %1,8 | 2 May 2024 |
36İzleyin | CVE-2023-38121İstismar yok | Inductive Automation Ignition OPC UA Quick Client Cross-Site Scripting Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-79 | Kritik9,0 | — | %1,2 | 2 May 2024 |
35İzleyin | CVE-2023-50219İstismar yok | Inductive Automation Ignition RunQuery Deserialization of Untrusted Data Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-502 | Yüksek8,8 | — | %1,5 | 2 May 2024 |
35İzleyin | CVE-2023-50232İstismar yok | Inductive Automation Ignition getParams Argument Injection Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-88 | Yüksek8,8 | — | %1,4 | 2 May 2024 |
35İzleyin | CVE-2023-38123İstismar yok | Inductive Automation Ignition OPC UA Quick Client Missing Authentication for Critical Function Authentication Bypass Vulnerabilityinductiveautomation · ignition · CWE-306 | Yüksek8,8 | — | %1,2 | 2 May 2024 |
35İzleyin | CVE-2023-50221İstismar yok | Inductive Automation Ignition ResponseParser SerializedResponse Deserialization of Untrusted Data Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-502 | Yüksek8,8 | — | %1,1 | 2 May 2024 |
35İzleyin | CVE-2023-50222İstismar yok | Inductive Automation Ignition ResponseParser Notification Deserialization of Untrusted Data Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-502 | Yüksek8,8 | — | %1,1 | 2 May 2024 |
35İzleyin | CVE-2022-1264İstismar yok | Inductive Automation Ignitioninductiveautomation · ignition · CWE-22 | Yüksek8,8 | — | %0,9 | 20 Tem 2022 |
35İzleyin | CVE-2023-39474İstismar yok | Inductive Automation Ignition downloadLaunchClientJar Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-494 | Yüksek8,8 | — | %0,6 | 2 May 2024 |
34İzleyin | CVE-2020-12004Silahlaştırılmış | The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignitinductiveautomation · ignition gateway · CWE-306 | Yüksek7,5 | — | %13,6 | 9 Haz 2020 |
31İzleyin | CVE-2022-35873İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202inductiveautomation · ignition · CWE-356 | Yüksek7,8 | — | %0,7 | 25 Tem 2022 |
31İzleyin | CVE-2022-35872İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202inductiveautomation · ignition · CWE-502 | Yüksek7,8 | — | %0,7 | 25 Tem 2022 |
- CVE-2023-3947558Planlayın
Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %64inductiveautomation · ignition2 May 2024
- CVE-2022-3586957Planlayın
This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022
KritikCVSS 9,8İstismar yokEPSS %60inductiveautomation · ignition25 Tem 2022
- CVE-2023-3947354Planlayın
Inductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %62inductiveautomation · ignition2 May 2024
- CVE-2023-3812453Planlayın
Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %60inductiveautomation · ignition2 May 2024
- CVE-2023-5022352Planlayın
Inductive Automation Ignition ExtendedDocumentCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %55inductiveautomation · ignition2 May 2024
- CVE-2023-5021852Planlayın
Inductive Automation Ignition ModuleInvoke Deserialization of Untrusted Data Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %55inductiveautomation · ignition2 May 2024
- CVE-2022-3587044Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202
YüksekCVSS 7,8İstismar yokEPSS %43inductiveautomation · ignition25 Tem 2022
- CVE-2022-3587143Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202
YüksekCVSS 7,8İstismar yokEPSS %39inductiveautomation · ignition25 Tem 2022
- CVE-2023-3947640Planlayın
Inductive Automation Ignition JavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %2inductiveautomation · ignition2 May 2024
- CVE-2022-3589040Planlayın
An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17.
KritikCVSS 9,8İstismar yokEPSS %2inductiveautomation · ignition15 Tem 2022
- CVE-2022-170439İzleyin
Inductive Automation Ignition
KritikCVSS 9,8İstismar yokEPSS %1inductiveautomation · ignition5 Ağu 2022
- CVE-2020-1064436İzleyin
The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8
YüksekCVSS 7,5SilahlaştırılmışEPSS %20inductiveautomation · ignition gateway9 Haz 2020
- CVE-2023-5023336İzleyin
Inductive Automation Ignition getJavaExecutable Directory Traversal Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %2inductiveautomation · ignition2 May 2024
- CVE-2023-5022036İzleyin
Inductive Automation Ignition Base64Element Deserialization of Untrusted Data Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %2inductiveautomation · ignition2 May 2024
- CVE-2023-3812136İzleyin
Inductive Automation Ignition OPC UA Quick Client Cross-Site Scripting Remote Code Execution Vulnerability
KritikCVSS 9,0İstismar yokEPSS %1inductiveautomation · ignition2 May 2024
- CVE-2023-5021935İzleyin
Inductive Automation Ignition RunQuery Deserialization of Untrusted Data Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %2inductiveautomation · ignition2 May 2024
- CVE-2023-5023235İzleyin
Inductive Automation Ignition getParams Argument Injection Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1inductiveautomation · ignition2 May 2024
- CVE-2023-3812335İzleyin
Inductive Automation Ignition OPC UA Quick Client Missing Authentication for Critical Function Authentication Bypass Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1inductiveautomation · ignition2 May 2024
- CVE-2023-5022135İzleyin
Inductive Automation Ignition ResponseParser SerializedResponse Deserialization of Untrusted Data Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1inductiveautomation · ignition2 May 2024
- CVE-2023-5022235İzleyin
Inductive Automation Ignition ResponseParser Notification Deserialization of Untrusted Data Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1inductiveautomation · ignition2 May 2024
- CVE-2022-126435İzleyin
Inductive Automation Ignition
YüksekCVSS 8,8İstismar yokEPSS %1inductiveautomation · ignition20 Tem 2022
- CVE-2023-3947435İzleyin
Inductive Automation Ignition downloadLaunchClientJar Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1inductiveautomation · ignition2 May 2024
- CVE-2020-1200434İzleyin
The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignit
YüksekCVSS 7,5SilahlaştırılmışEPSS %14inductiveautomation · ignition gateway9 Haz 2020
- CVE-2022-3587331İzleyin
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202
YüksekCVSS 7,8İstismar yokEPSS %1inductiveautomation · ignition25 Tem 2022
- CVE-2022-3587231İzleyin
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202
YüksekCVSS 7,8İstismar yokEPSS %1inductiveautomation · ignition25 Tem 2022