← Back to home
ICSA-20-147-01  ·  Published 2020-06-30  ·  View on CISA ICS-CERT ↗

Inductive Automation Ignition (Update B)

CVSS 9.8 CRITICAL

Remediations

  • Inductive Automation recommends upgrading the Ignition software to v8.0.10
  • For those running v7.9.x, it is recommended to upgrade the Ignition software to v7.9.14
  • Please note CVE-2020-14479 does not have a fix in place. Induction Automation plans to correct this vulnerability in future product versions. It is recommended to restrict interaction with the service to trusted machines. Only clients and servers with a legitimate procedural relationship should be permitted to communicate with the service. This can be done in various ways, most notably with firewall rules/allow listing. For more information regarding software and patches, please refer to the specified version in Inductive Automation's release notes.

Affected Vendors

Inductive Automation

Affected Products (2)

Inductive Automation · Inductive Automation Ignition 8 Gateway < 8.0.10
Inductive Automation · Inductive Automation Ignition 7 Gateway < 7.9.14

Affected Sectors

Critical Manufacturing, Energy, Information Technology

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more