CVE-2020-14479: ICSA-20-147-01 Inductive Automation Ignition (Update B)
Published Apr 1, 2022
·Updated
Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server
Affected Software
4 affected components
Inductive Automation Ignition 7 Gateway versions prior to 7.9.14
Inductive Automation Ignition 8 Gateway versions prior to 8.0.10
inductiveautomation Ignition>=7.0.0<7.9.14
inductiveautomation Ignition>=8.0.1<=8.0.10
Remediation
Patch Available
Event History
Apr 1, 2022
CVE Published
via MITRE·10:17 PM
Data Sourced
via MITRE·10:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-14479?
CVE-2020-14479 has a high severity rating due to its potential for exposing sensitive information.
2
How do I fix CVE-2020-14479?
To fix CVE-2020-14479, upgrade to Ignition versions 7.9.14 or later, or 8.0.10 or later.
3
What software versions are affected by CVE-2020-14479?
CVE-2020-14479 affects Inductive Automation Ignition versions prior to 7.9.14 and 8.0.10.
4
What is the impact of CVE-2020-14479?
The impact of CVE-2020-14479 is that unauthorized users can obtain sensitive information due to insufficient authentication.
5
Who is the vendor for CVE-2020-14479?
The vendor for CVE-2020-14479 is Inductive Automation.