Inductive Automation Ignition OPC UA Quick Client Cross-Site Scripting Remote Code Execution Vulnerability
CVE-2023-38121

9CRITICAL

Key Information:

Status
Vendor
CVE Published:
3 May 2024

What is CVE-2023-38121?

A Cross-Site Scripting vulnerability exists in Inductive Automation Ignition's OPC UA Quick Client, allowing remote attackers to execute arbitrary code. This flaw arises from insufficient validation of user-supplied input within the web interface's id parameter. By crafting malicious links or files that prompt user interaction, attackers can leverage this vulnerability to inject scripts that run with SYSTEM privileges, leading to potentially severe security risks for the affected installations.

Affected Version(s)

Ignition 8.1.24

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.