CVE-2022-1264: Inductive Automation Ignition
Published Jul 20, 2022
·Updated
The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code.
Affected Software
3 affected components
inductiveautomation Ignition>=8.0.4<8.1.10
Inductive Automation Ignition: All 8.0 versions after 8.0.4
Inductive Automation Ignition: All 8.1 versions prior to 8.1.10
Remediation
Information
Inductive Automation recommends users upgrade the Ignition software to 8.1.10 or later.
Event History
Jul 20, 2022
CVE Published
via MITRE·03:34 PM
Data Sourced
via MITRE·03:34 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1264?
CVE-2022-1264 has a critical severity rating due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2022-1264?
To fix CVE-2022-1264, you should upgrade to Ignition version 8.1.10 or higher, or update any 8.0 version beyond 8.0.4.
3
What versions of Ignition are affected by CVE-2022-1264?
CVE-2022-1264 affects all 8.0 versions after 8.0.4 and all 8.1 versions prior to 8.1.10.
4
What impact does CVE-2022-1264 have on security?
CVE-2022-1264 can have a significant impact on security by allowing an attacker to execute arbitrary code on the affected systems.
5
Who is the vendor for CVE-2022-1264?
The vendor for CVE-2022-1264 is Inductive Automation, the company behind the Ignition platform.