Inductive Automation Ignition OPC UA Quick Client Missing Authentication for Critical Function Authentication Bypass Vulnerability
CVE-2023-38123

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
3 May 2024

What is CVE-2023-38123?

The Ignition OPC UA Quick Client by Inductive Automation has a vulnerability that enables attackers to bypass authentication measures under certain conditions. This security issue stems from an insufficient authentication mechanism present in the server configuration, particularly affecting the password change functionality. Successful exploitation requires a target to visit a malicious web page or to open a malicious file, allowing an attacker to gain unauthorized access to critical functionalities of the system easily. Addressing this flaw is essential for maintaining the integrity and security of installations running the affected software.

Affected Version(s)

Ignition 8.1.24

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.