ZDI-CAN-22028: ZDI-24-184: Inductive Automation Ignition getParams Argument Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in that the target must connect to a malicious server. The specific flaw exists within the getParams method. The issue results from the lack of proper validation of a user-supplied string before using it to prepare an argument for a system call. An attacker can leverage this vulnerability to execute code in the context of the current user.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in that the target must connect to a malicious server. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-50232.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22028?
ZDI-CAN-22028 is categorized as a critical vulnerability due to the potential for remote code execution.
How do I fix ZDI-CAN-22028?
To fix ZDI-CAN-22028, users should update their Inductive Automation Ignition software to the latest available version that includes patches.
What types of systems are affected by ZDI-CAN-22028?
ZDI-CAN-22028 affects installations of Inductive Automation Ignition that have not been updated to include the necessary security fixes.
What is the potential impact of ZDI-CAN-22028?
Exploitation of ZDI-CAN-22028 can allow attackers to execute arbitrary code on the affected systems, leading to unauthorized access or control.
Is user interaction required to exploit ZDI-CAN-22028?
Yes, user interaction is required as the target must connect to a malicious server for the vulnerability to be exploited.