CVE-2022-1704: Inductive Automation Ignition
Published Aug 5, 2022
·Updated
Due to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a XXE attack while restoring the backup.
Affected Software
4 affected components
Inductive Automation Ignition: All versions from 8.1 to those prior to v8.1.8
Inductive Automation Ignition: All 7.9 versions prior to v7.9.21
inductiveautomation Ignition>=7.9.0<7.9.21
inductiveautomation Ignition>=8.1.0<8.1.8
Remediation
Information
Inductive Automation recommends users upgrade the Ignition software to the latest version:
Inductive Automation Ignition: Version 8.1.9 or later
Inductive Automation Ignition: Version 7.9.21 or later
Event History
Aug 5, 2022
CVE Published
via MITRE·03:25 PM
Data Sourced
via MITRE·03:25 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1704?
CVE-2022-1704 is rated as a critical vulnerability due to its potential to allow an XXE attack.
2
How do I fix CVE-2022-1704?
To resolve CVE-2022-1704, update Inductive Automation Ignition to versions 8.1.8 or later, or 7.9.21 or later.
3
What types of attacks are possible with CVE-2022-1704?
CVE-2022-1704 may enable attackers to perform XML External Entity (XXE) attacks during the backup restoration process.
4
Which versions of Ignition are affected by CVE-2022-1704?
CVE-2022-1704 affects Inductive Automation Ignition versions prior to 8.1.8 and 7.9 versions prior to 7.9.21.
5
Is CVE-2022-1704 a widespread vulnerability?
Yes, CVE-2022-1704 affects multiple versions of the widely used Inductive Automation Ignition software.