ICSA-20-112-01
·
Published 2020-04-21
·
View on CISA ICS-CERT ↗
Inductive Automation Ignition
CVSS 9.1
CRITICAL
Risk Summary
Successful exploitation of this vulnerability could allow an attacker to write endless log statements into the database, which could result in a denial-of-service condition.
CVEs (1)
Remediations
- Upgrade Ignition 8 Gateway to v8.0.10
- Reference vendor website
- If running the Perspective Module, set “perspective.routes” to a priority level of WARN or higher. The exploit triggers the code path that logs a message with priority level INFO.
- For gateways that are deployed behind a web application firewall or reverse proxy, deploy a rule to deny access to all gateway HTTP requests that include the path: /data/perspective/print-to-log.
Affected Vendors
Inductive Automation
Affected Products (1)
Inductive Automation
·
Ignition 8 Gateway
< 8.0.10
Affected Sectors
Critical Manufacturing, Energy, Information Technology
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more