Inductive Automation Ignition getJavaExecutable Directory Traversal Remote Code Execution Vulnerability
CVE-2023-50233
What is CVE-2023-50233?
A remote code execution vulnerability exists within the getJavaExecutable method of Inductive Automation Ignition, allowing attackers to exploit this flaw through directory traversal. By failing to properly validate a user-supplied path, the vulnerability enables the execution of arbitrary code on targeted systems when they connect to a malicious server. Exploiting this flaw requires user interaction, increasing the complexity but not the severity of potential attacks. This vulnerability jeopardizes the integrity and security of affected installations, making timely updates and mitigations essential.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Ignition 8.1.31
References
CVSS V3.1
Timeline
Vulnerability published
