CVE-2023-39477: (0Day) (Pwn2Own) Inductive Automation Ignition ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability
Inductive Automation Ignition ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Inductive Automation Ignition. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of OPC UA ConditionRefresh requests. By sending a large number of requests, an attacker can consume all available resources on the server. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-20499.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-39477?
CVE-2023-39477 is classified as a denial-of-service vulnerability that can significantly disrupt the functionality of affected systems.
How do I fix CVE-2023-39477?
To mitigate CVE-2023-39477, upgrade to the latest version of Inductive Automation Ignition as outlined in the release notes.
What types of installations are affected by CVE-2023-39477?
CVE-2023-39477 affects installations of Inductive Automation Ignition without requiring authentication to exploit.
Can CVE-2023-39477 be exploited remotely?
Yes, CVE-2023-39477 can be exploited remotely by attackers to create denial-of-service conditions.
What impact does CVE-2023-39477 have on system availability?
CVE-2023-39477 can cause resource exhaustion leading to a denial-of-service, severely impacting the availability of the affected installation.