Inductive Automation Ignition ResponseParser SerializedResponse Deserialization of Untrusted Data Remote Code Execution Vulnerability
CVE-2023-50221
8.8HIGH
What is CVE-2023-50221?
A vulnerability exists within Inductive Automation Ignition that allows for the deserialization of untrusted data via the ResponseParser method. This flaw can be exploited by remote attackers, provided that a user connects to a malicious server, potentially leading to arbitrary code execution in the context of the affected user. The lack of adequate validation of user-supplied data increases the severity of this issue, making it essential for users and administrators to implement appropriate security measures and stay informed about updates and patches.
Affected Version(s)
Ignition 8.1.31
