First published: Fri Apr 01 2022(Updated: )
Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Inductive Automation Ignition | ||
Inductive Automation Ignition | ||
Inductive Automation Ignition | >=7.0.0<7.9.14 | |
Inductive Automation Ignition | >=8.0.1<=8.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14479 has a high severity rating due to its potential for exposing sensitive information.
To fix CVE-2020-14479, upgrade to Ignition versions 7.9.14 or later, or 8.0.10 or later.
CVE-2020-14479 affects Inductive Automation Ignition versions prior to 7.9.14 and 8.0.10.
The impact of CVE-2020-14479 is that unauthorized users can obtain sensitive information due to insufficient authentication.
The vendor for CVE-2020-14479 is Inductive Automation.