Inductive Automation Ignition downloadLaunchClientJar Remote Code Execution Vulnerability
CVE-2023-39474
8.8HIGH
What is CVE-2023-39474?
Inductive Automation Ignition features a vulnerability within the downloadLaunchClientJar function, allowing remote attackers to execute arbitrary code on systems where the software is installed. The vulnerability arises due to insufficient validation of a remote JAR file before it is loaded. For successful exploitation, user interaction is required, as the target device must connect to a malicious server. By leveraging this flaw, attackers can execute code with the privileges of the current user, posing significant risks to device security and data integrity.
Affected Version(s)
Ignition 8.1.24-RC / 1.1.24-RC
