Inductive Automation Ignition downloadLaunchClientJar Remote Code Execution Vulnerability
CVE-2023-39474
What is CVE-2023-39474?
Inductive Automation Ignition features a vulnerability within the downloadLaunchClientJar function, allowing remote attackers to execute arbitrary code on systems where the software is installed. The vulnerability arises due to insufficient validation of a remote JAR file before it is loaded. For successful exploitation, user interaction is required, as the target device must connect to a malicious server. By leveraging this flaw, attackers can execute code with the privileges of the current user, posing significant risks to device security and data integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Ignition 8.1.24-RC / 1.1.24-RC
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
