ICSA-20-147-01 Inductive Automation Ignition (Update B)
CVE-2020-14479
5.3MEDIUM
What is CVE-2020-14479?
Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server
Affected Version(s)
Ignition 7 Gateway All < 7.9.14
Ignition 8 Gateway All < 8.0.10
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Pedro Ribeiro, Radek Domanski, Chris Anastasio (muffin), and Steven Seeley (mr_me) working with Trend Micro’s Zero Day Initiative reported these vulnerabilities to CISA.
