Inductive Automation Ignition OPC UA Quick Client Permissive Cross-domain Policy Remote Code Execution Vulnerability
CVE-2023-38122

7.2HIGH

Key Information:

Status
Vendor
CVE Published:
3 May 2024

What is CVE-2023-38122?

A vulnerability has been identified in the Inductive Automation Ignition OPC UA Quick Client which permits remote attackers to execute arbitrary code. This exploits a misconfiguration within the web server related to Content Security Policy headers. Although the exploit requires authentication, the existing measures can be circumvented, providing a pathway for code execution within the SYSTEM context. The potential for this vulnerability to be leveraged in combination with other weaknesses poses significant security risks.

Affected Version(s)

Ignition 8.1.24

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.