CVE-2022-36126: High severity inductive automation ignition vulnerability
An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. The ScriptInvoke function allows remote attackers to execute arbitrary code by supplying a Python script.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36126?
CVE-2022-36126 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2022-36126?
To mitigate the effects of CVE-2022-36126, upgrade Inductive Automation Ignition to version 7.9.20 or 8.1.17 or later.
What software versions are affected by CVE-2022-36126?
CVE-2022-36126 affects Inductive Automation Ignition versions prior to 7.9.20 and versions between 8.0.1 and 8.1.16.
Can CVE-2022-36126 be exploited remotely?
Yes, CVE-2022-36126 can be exploited remotely by attackers leveraging the vulnerable ScriptInvoke function to execute arbitrary code.
What type of attack does CVE-2022-36126 enable?
CVE-2022-36126 enables remote code execution attacks, allowing unauthorized execution of Python scripts.