CVE-2015-0995: Medium severity inductive automation ignition vulnerability
Published Apr 3, 2015
·Updated
Inductive Automation Ignition 7.7.2 uses MD5 password hashes, which makes it easier for context-dependent attackers to obtain access via a brute-force attack.
Affected Software
1 affected component
inductiveautomation Ignition=7.7.2
Event History
Apr 3, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0995?
CVE-2015-0995 has been assigned a medium severity level due to its potential for password cracking via brute-force attacks.
2
How do I fix CVE-2015-0995?
To fix CVE-2015-0995, upgrade to a version of Inductive Automation Ignition that uses stronger password hashing algorithms instead of MD5.
3
What type of attack can exploit CVE-2015-0995?
CVE-2015-0995 can be exploited via brute-force attacks due to the use of weak MD5 password hashes.
4
Which software version is affected by CVE-2015-0995?
CVE-2015-0995 specifically affects Inductive Automation Ignition version 7.7.2.
5
What are the risks of leaving CVE-2015-0995 unpatched?
Leaving CVE-2015-0995 unpatched increases the risk of unauthorized access to sensitive systems through compromised password security.