ZDI-CAN-17587: ZDI-23-1045: (0Day) Inductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Aug 8, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
Inductive Automation Ignition
Event History
Aug 8, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Mar 28, 2025
Advisory Published
via ZDI·02:08 AM
Frequently Asked Questions
1
What is the severity of ZDI-CAN-17587?
The severity of ZDI-CAN-17587 is high, as it allows remote code execution on affected systems.
2
How do I fix ZDI-CAN-17587?
To fix ZDI-CAN-17587, you need to apply the latest security updates provided by Inductive Automation for Ignition.
3
Who is affected by ZDI-CAN-17587?
ZDI-CAN-17587 affects installations of Inductive Automation Ignition 8 that are not properly secured.
4
Can ZDI-CAN-17587 be exploited without authentication?
No, ZDI-CAN-17587 requires authentication to exploit the vulnerability.
5
What are the potential impacts of ZDI-CAN-17587?
The potential impacts of ZDI-CAN-17587 include unauthorized remote code execution, compromising system integrity.