Inductive Automation Ignition getJavaExecutable Directory Traversal Remote Code Execution Vulnerability
CVE-2023-50233

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
3 May 2024

What is CVE-2023-50233?

A remote code execution vulnerability exists within the getJavaExecutable method of Inductive Automation Ignition, allowing attackers to exploit this flaw through directory traversal. By failing to properly validate a user-supplied path, the vulnerability enables the execution of arbitrary code on targeted systems when they connect to a malicious server. Exploiting this flaw requires user interaction, increasing the complexity but not the severity of potential attacks. This vulnerability jeopardizes the integrity and security of affected installations, making timely updates and mitigations essential.

Affected Version(s)

Ignition 8.1.31

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.