CVE-2015-0994: Medium severity inductive automation ignition vulnerability
Published Apr 3, 2015
·Updated
Inductive Automation Ignition 7.7.2 allows remote authenticated users to bypass a brute-force protection mechanism by using different session ID values in a series of HTTP requests.
Affected Software
1 affected component
inductiveautomation Ignition=7.7.2
Event History
Apr 3, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0994?
CVE-2015-0994 is classified as a Medium severity vulnerability due to its potential for exploitation by authenticated users.
2
How do I fix CVE-2015-0994?
To mitigate CVE-2015-0994, upgrade to a later version of Ignition that addresses this vulnerability.
3
Who is affected by CVE-2015-0994?
CVE-2015-0994 affects users of Inductive Automation Ignition version 7.7.2.
4
What type of vulnerability is CVE-2015-0994?
CVE-2015-0994 is a vulnerability that allows remote authenticated users to bypass brute-force protection.
5
What is the impact of CVE-2015-0994?
The impact of CVE-2015-0994 can lead to unauthorized access by exploiting session management weaknesses.