← Back to home
ICSA-20-112-01  ·  Published 2020-04-21  ·  View on CISA ICS-CERT ↗

Inductive Automation Ignition

CVSS 9.1 CRITICAL

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to write endless log statements into the database, which could result in a denial-of-service condition.

CVEs (1)

Remediations

  • Upgrade Ignition 8 Gateway to v8.0.10
  • Reference vendor website
  • If running the Perspective Module, set “perspective.routes” to a priority level of WARN or higher. The exploit triggers the code path that logs a message with priority level INFO.
  • For gateways that are deployed behind a web application firewall or reverse proxy, deploy a rule to deny access to all gateway HTTP requests that include the path: /data/perspective/print-to-log.

Affected Vendors

Inductive Automation

Affected Products (1)

Inductive Automation · Ignition 8 Gateway < 8.0.10

Affected Sectors

Critical Manufacturing, Energy, Information Technology

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more