First published: Tue Apr 28 2020(Updated: )
An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This results in consuming the entire available hard-disk space on the Ignition 8 Gateway (versions prior to 8.0.10), causing a denial-of-service condition.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Inductive Automation Ignition | >=8.0<8.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10641 has a high severity rating due to its potential for denial-of-service caused by unprotected logging.
To fix CVE-2020-10641, upgrade to Ignition 8 Gateway version 8.0.10 or later, which addresses the vulnerability.
The impact of CVE-2020-10641 includes the potential complete consumption of disk space, leading to service outages.
All versions of Inductive Automation's Ignition Gateway prior to 8.0.10 are affected by CVE-2020-10641.
Yes, CVE-2020-10641 can be exploited remotely by an attacker who accesses the unprotected logging route.