Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ignition Gateway HIGH 7.5
CVE-2020-12004EPSS 14%

The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gat…

Fix: 7.9.14 / 8.0.10+
Fix from $1,950 2020-06-09
Ignition Gateway HIGH 7.5
CVE-2020-10644EPSS 20%

The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (…

Fix: 7.9.14 / 8.0.10+
Fix from $1,950 2020-06-09
Ignition Gateway HIGH 7.5
CVE-2020-12000

The affected product is vulnerable to the handling of serialized data. The issue results from the lack of proper validation of user-supplied data, wh…

Fix: 7.9.14 / 8.0.10+
Fix from $1,950 2020-06-09
Ignition Gateway HIGH 7.5
CVE-2020-10641

An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This res…

Fix: 8.0.10+
Fix from $1,950 2020-04-28
Ignition MEDIUM 5.0
CVE-2015-0995

Inductive Automation Ignition 7.7.2 uses MD5 password hashes, which makes it easier for context-dependent attackers to obtain access via a brute-forc…

Mitigation only
Fix from $1,600 2015-04-03
Ignition MEDIUM 6.4
CVE-2015-0993

Inductive Automation Ignition 7.7.2 does not terminate a session upon a logout action, which allows remote attackers to bypass intended access restri…

Mitigation only
Fix from $1,600 2015-04-03
Ignition MEDIUM 5.0
CVE-2015-0991

Inductive Automation Ignition 7.7.2 allows remote attackers to obtain sensitive information by reading an error message about an unhandled exception,…

Mitigation only
Fix from $1,600 2015-04-03