CVE-2015-0993: Medium severity inductive automation ignition vulnerability
Inductive Automation Ignition 7.7.2 does not terminate a session upon a logout action, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability associated with CVE-2015-0993?
CVE-2015-0993 describes a session management flaw in Inductive Automation Ignition 7.7.2 that fails to terminate user sessions upon logout.
What are the risks of CVE-2015-0993?
The risks of CVE-2015-0993 include unauthorized access to sensitive information and control over the Ignition environment due to lingering session states.
How can I mitigate CVE-2015-0993?
To mitigate CVE-2015-0993, ensure that users are logged out of sessions and consider implementing additional access control measures.
What versions are affected by CVE-2015-0993?
The affected version of software by CVE-2015-0993 is Inductive Automation Ignition 7.7.2.
Is there a patch available for CVE-2015-0993?
Yes, it is recommended to update to a fixed version of Inductive Automation Ignition to prevent exploitation of CVE-2015-0993.