First published: Fri Aug 05 2022(Updated: )
Due to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a XXE attack while restoring the backup.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Inductiveautomation Ignition | >=7.9.0<7.9.21 | |
Inductiveautomation Ignition | >=8.1.0<8.1.8 | |
Inductive Automation Ignition: All versions from 8.1 to those prior to v8.1.8 | ||
Inductive Automation Ignition: All 7.9 versions prior to v7.9.21 |
Inductive Automation recommends users upgrade the Ignition software to the latest version: Inductive Automation Ignition: Version 8.1.9 or later Inductive Automation Ignition: Version 7.9.21 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.