Skip to main content

Vendor/product archive

inductiveautomation / ignition CVEs

Beta · best-effort

35 CVEs tagged to inductiveautomation / ignition5 Critical, 20 High, 9 Medium, 1 Low, 0 Unrated.

CVE-2025-13913

Published Mar 12, 2026

A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious code.

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2023-50233

Published May 3, 2024

Inductive Automation Ignition getJavaExecutable Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on af…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50232

Published May 3, 2024

Inductive Automation Ignition getParams Argument Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50223

Published May 3, 2024

Inductive Automation Ignition ExtendedDocumentCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute ar…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50222

Published May 3, 2024

Inductive Automation Ignition ResponseParser Notification Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exec…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50221

Published May 3, 2024

Inductive Automation Ignition ResponseParser SerializedResponse Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50220

Published May 3, 2024

Inductive Automation Ignition Base64Element Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50219

Published May 3, 2024

Inductive Automation Ignition RunQuery Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50218

Published May 3, 2024

Inductive Automation Ignition ModuleInvoke Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39477

Published May 3, 2024

Inductive Automation Ignition ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39476

Published May 3, 2024

Inductive Automation Ignition JavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-39475

Published May 3, 2024

Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attack…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-39474

Published May 3, 2024

Inductive Automation Ignition downloadLaunchClientJar Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39473

Published May 3, 2024

Inductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39472

Published May 3, 2024

Inductive Automation Ignition SimpleXMLReader XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38124

Published May 3, 2024

Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38123

Published May 3, 2024

Inductive Automation Ignition OPC UA Quick Client Missing Authentication for Critical Function Authentication Bypass Vulnerability. This vulnerability allows remote attackers to b…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38122

Published May 3, 2024

Inductive Automation Ignition OPC UA Quick Client Permissive Cross-domain Policy Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitra…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38121

Published May 3, 2024

Inductive Automation Ignition OPC UA Quick Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-1704

Published Aug 5, 2022

Due to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a XXE attack while restoring the…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-35873

Published Jul 25, 2022

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). User interaction is required…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-35872

Published Jul 25, 2022

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). User interaction is required…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-35871

Published Jul 25, 2022

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not require…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-35870

Published Jul 25, 2022

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Although authentication is re…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-35869

Published Jul 25, 2022

This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 35 CVEsPage 1 of 2