ICSA-20-147-01 Inductive Automation Ignition (Update B)
CVE-2020-14479

5.3MEDIUM

What is CVE-2020-14479?

Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server

Affected Version(s)

Ignition 7 Gateway All < 7.9.14

Ignition 8 Gateway All < 8.0.10

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pedro Ribeiro, Radek Domanski, Chris Anastasio (muffin), and Steven Seeley (mr_me) working with Trend Micro’s Zero Day Initiative reported these vulnerabilities to CISA.
.