Записи inductiveautomation
40 опубликованных записей вендора inductiveautomation.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 5 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-502 Deserialization of Untrusted Data14
- CWE-306 Missing Authentication for Critical Function4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-254 7PK - Security Features2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
40 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
58В плане | CVE-2023-39475Эксплойта нет | Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-502 | Критическая9,8 | — | 64,1 % | 2 мая 2024 г. |
57В плане | CVE-2022-35869Эксплойта нет | This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022inductiveautomation · ignition · CWE-288 | Критическая9,8 | — | 60,3 % | 25 июл. 2022 г. |
54В плане | CVE-2023-39473Эксплойта нет | Inductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-502 | Высокая8,8 | — | 62,5 % | 2 мая 2024 г. |
53В плане | CVE-2023-38124Эксплойта нет | Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-749 | Высокая8,8 | — | 59,6 % | 2 мая 2024 г. |
52В плане | CVE-2023-50223Эксплойта нет | Inductive Automation Ignition ExtendedDocumentCodec Deserialization of Untrusted Data Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-502 | Высокая8,8 | — | 55,2 % | 2 мая 2024 г. |
52В плане | CVE-2023-50218Эксплойта нет | Inductive Automation Ignition ModuleInvoke Deserialization of Untrusted Data Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-502 | Высокая8,8 | — | 55,0 % | 2 мая 2024 г. |
44В плане | CVE-2022-35870Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202inductiveautomation · ignition · CWE-502 | Высокая7,8 | — | 43,3 % | 25 июл. 2022 г. |
43В плане | CVE-2022-35871Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202inductiveautomation · ignition · CWE-306 | Высокая7,8 | — | 39,2 % | 25 июл. 2022 г. |
40В плане | CVE-2023-39476Эксплойта нет | Inductive Automation Ignition JavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-502 | Критическая9,8 | — | 2,2 % | 2 мая 2024 г. |
40В плане | CVE-2022-35890Эксплойта нет | An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17.inductiveautomation · ignition · CWE-863 | Критическая9,8 | — | 2,0 % | 15 июл. 2022 г. |
39Наблюдать | CVE-2022-1704Эксплойта нет | Inductive Automation Ignitioninductiveautomation · ignition · CWE-611 | Критическая9,8 | — | 1,0 % | 5 авг. 2022 г. |
36Наблюдать | CVE-2020-10644Готовый эксплойт | The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 inductiveautomation · ignition gateway · CWE-502 | Высокая7,5 | — | 20,2 % | 9 июн. 2020 г. |
36Наблюдать | CVE-2023-50233Эксплойта нет | Inductive Automation Ignition getJavaExecutable Directory Traversal Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-22 | Высокая8,8 | — | 2,1 % | 2 мая 2024 г. |
36Наблюдать | CVE-2023-50220Эксплойта нет | Inductive Automation Ignition Base64Element Deserialization of Untrusted Data Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-502 | Высокая8,8 | — | 1,8 % | 2 мая 2024 г. |
36Наблюдать | CVE-2023-38121Эксплойта нет | Inductive Automation Ignition OPC UA Quick Client Cross-Site Scripting Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-79 | Критическая9,0 | — | 1,2 % | 2 мая 2024 г. |
35Наблюдать | CVE-2023-50219Эксплойта нет | Inductive Automation Ignition RunQuery Deserialization of Untrusted Data Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-502 | Высокая8,8 | — | 1,5 % | 2 мая 2024 г. |
35Наблюдать | CVE-2023-50232Эксплойта нет | Inductive Automation Ignition getParams Argument Injection Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-88 | Высокая8,8 | — | 1,4 % | 2 мая 2024 г. |
35Наблюдать | CVE-2023-38123Эксплойта нет | Inductive Automation Ignition OPC UA Quick Client Missing Authentication for Critical Function Authentication Bypass Vulnerabilityinductiveautomation · ignition · CWE-306 | Высокая8,8 | — | 1,2 % | 2 мая 2024 г. |
35Наблюдать | CVE-2023-50221Эксплойта нет | Inductive Automation Ignition ResponseParser SerializedResponse Deserialization of Untrusted Data Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-502 | Высокая8,8 | — | 1,1 % | 2 мая 2024 г. |
35Наблюдать | CVE-2023-50222Эксплойта нет | Inductive Automation Ignition ResponseParser Notification Deserialization of Untrusted Data Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-502 | Высокая8,8 | — | 1,1 % | 2 мая 2024 г. |
35Наблюдать | CVE-2022-1264Эксплойта нет | Inductive Automation Ignitioninductiveautomation · ignition · CWE-22 | Высокая8,8 | — | 0,9 % | 20 июл. 2022 г. |
35Наблюдать | CVE-2023-39474Эксплойта нет | Inductive Automation Ignition downloadLaunchClientJar Remote Code Execution Vulnerabilityinductiveautomation · ignition · CWE-494 | Высокая8,8 | — | 0,6 % | 2 мая 2024 г. |
34Наблюдать | CVE-2020-12004Готовый эксплойт | The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignitinductiveautomation · ignition gateway · CWE-306 | Высокая7,5 | — | 13,6 % | 9 июн. 2020 г. |
31Наблюдать | CVE-2022-35873Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202inductiveautomation · ignition · CWE-356 | Высокая7,8 | — | 0,7 % | 25 июл. 2022 г. |
31Наблюдать | CVE-2022-35872Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202inductiveautomation · ignition · CWE-502 | Высокая7,8 | — | 0,7 % | 25 июл. 2022 г. |
- CVE-2023-3947558В плане
Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 64 %inductiveautomation · ignition2 мая 2024 г.
- CVE-2022-3586957В плане
This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022
КритическаяCVSS 9,8Эксплойта нетEPSS 60 %inductiveautomation · ignition25 июл. 2022 г.
- CVE-2023-3947354В плане
Inductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 62 %inductiveautomation · ignition2 мая 2024 г.
- CVE-2023-3812453В плане
Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 60 %inductiveautomation · ignition2 мая 2024 г.
- CVE-2023-5022352В плане
Inductive Automation Ignition ExtendedDocumentCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 55 %inductiveautomation · ignition2 мая 2024 г.
- CVE-2023-5021852В плане
Inductive Automation Ignition ModuleInvoke Deserialization of Untrusted Data Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 55 %inductiveautomation · ignition2 мая 2024 г.
- CVE-2022-3587044В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202
ВысокаяCVSS 7,8Эксплойта нетEPSS 43 %inductiveautomation · ignition25 июл. 2022 г.
- CVE-2022-3587143В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202
ВысокаяCVSS 7,8Эксплойта нетEPSS 39 %inductiveautomation · ignition25 июл. 2022 г.
- CVE-2023-3947640В плане
Inductive Automation Ignition JavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %inductiveautomation · ignition2 мая 2024 г.
- CVE-2022-3589040В плане
An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %inductiveautomation · ignition15 июл. 2022 г.
- CVE-2022-170439Наблюдать
Inductive Automation Ignition
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %inductiveautomation · ignition5 авг. 2022 г.
- CVE-2020-1064436Наблюдать
The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8
ВысокаяCVSS 7,5Готовый эксплойтEPSS 20 %inductiveautomation · ignition gateway9 июн. 2020 г.
- CVE-2023-5023336Наблюдать
Inductive Automation Ignition getJavaExecutable Directory Traversal Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %inductiveautomation · ignition2 мая 2024 г.
- CVE-2023-5022036Наблюдать
Inductive Automation Ignition Base64Element Deserialization of Untrusted Data Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %inductiveautomation · ignition2 мая 2024 г.
- CVE-2023-3812136Наблюдать
Inductive Automation Ignition OPC UA Quick Client Cross-Site Scripting Remote Code Execution Vulnerability
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %inductiveautomation · ignition2 мая 2024 г.
- CVE-2023-5021935Наблюдать
Inductive Automation Ignition RunQuery Deserialization of Untrusted Data Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %inductiveautomation · ignition2 мая 2024 г.
- CVE-2023-5023235Наблюдать
Inductive Automation Ignition getParams Argument Injection Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %inductiveautomation · ignition2 мая 2024 г.
- CVE-2023-3812335Наблюдать
Inductive Automation Ignition OPC UA Quick Client Missing Authentication for Critical Function Authentication Bypass Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %inductiveautomation · ignition2 мая 2024 г.
- CVE-2023-5022135Наблюдать
Inductive Automation Ignition ResponseParser SerializedResponse Deserialization of Untrusted Data Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %inductiveautomation · ignition2 мая 2024 г.
- CVE-2023-5022235Наблюдать
Inductive Automation Ignition ResponseParser Notification Deserialization of Untrusted Data Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %inductiveautomation · ignition2 мая 2024 г.
- CVE-2022-126435Наблюдать
Inductive Automation Ignition
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %inductiveautomation · ignition20 июл. 2022 г.
- CVE-2023-3947435Наблюдать
Inductive Automation Ignition downloadLaunchClientJar Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %inductiveautomation · ignition2 мая 2024 г.
- CVE-2020-1200434Наблюдать
The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignit
ВысокаяCVSS 7,5Готовый эксплойтEPSS 14 %inductiveautomation · ignition gateway9 июн. 2020 г.
- CVE-2022-3587331Наблюдать
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %inductiveautomation · ignition25 июл. 2022 г.
- CVE-2022-3587231Наблюдать
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %inductiveautomation · ignition25 июл. 2022 г.