First published: Fri Apr 03 2015(Updated: )
Inductive Automation Ignition 7.7.2 allows remote authenticated users to bypass a brute-force protection mechanism by using different session ID values in a series of HTTP requests.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Inductive Automation Ignition | =7.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0994 is classified as a Medium severity vulnerability due to its potential for exploitation by authenticated users.
To mitigate CVE-2015-0994, upgrade to a later version of Ignition that addresses this vulnerability.
CVE-2015-0994 affects users of Inductive Automation Ignition version 7.7.2.
CVE-2015-0994 is a vulnerability that allows remote authenticated users to bypass brute-force protection.
The impact of CVE-2015-0994 can lead to unauthorized access by exploiting session management weaknesses.