Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2020-12004EPSS 14% The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gat… Ignition Gateway 7.9.14 / 8.0.10+ Fix from $1,9502020-06-09 HIGH 7.5 CVE-2020-10644EPSS 20% The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (… Ignition Gateway 7.9.14 / 8.0.10+ Fix from $1,9502020-06-09 HIGH 7.5 CVE-2020-12000 The affected product is vulnerable to the handling of serialized data. The issue results from the lack of proper validation of user-supplied data, wh… Ignition Gateway 7.9.14 / 8.0.10+ Fix from $1,9502020-06-09 HIGH 7.5 CVE-2020-10641 An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This res… Ignition Gateway 8.0.10+ Fix from $1,9502020-04-28 MEDIUM 5.0 CVE-2015-0995 Inductive Automation Ignition 7.7.2 uses MD5 password hashes, which makes it easier for context-dependent attackers to obtain access via a brute-forc… Ignition Mitigation only Fix from $1,6002015-04-03 MEDIUM 6.4 CVE-2015-0993 Inductive Automation Ignition 7.7.2 does not terminate a session upon a logout action, which allows remote attackers to bypass intended access restri… Ignition Mitigation only Fix from $1,6002015-04-03 MEDIUM 5.0 CVE-2015-0991 Inductive Automation Ignition 7.7.2 allows remote attackers to obtain sensitive information by reading an error message about an unhandled exception,… Ignition Mitigation only Fix from $1,6002015-04-03