Beschreibung
Multiple serious vulnerabilities have been found in Inductive Automation Ignition. Malicious users can exploit these vulnerabilities to bypass security restrictions, obtain sensitive information or inject arbitrary code.
Below is a complete list of vulnerabilities
- Improper passwords handling can be exploited remotely via an unknown vectors;
- An unknown vulnerability can be exploited remotely vai a specially designed session ID’s;
- Improper session handling can be exploited remotely via vectors related to logout action;
- Improper Server credentials storaging and other unknown vulnerability can be exploited remotely via error messages manipulation;
- XSS vulnerability can be exploited remotely via an unspecified vectors.
Ursprüngliche Informationshinweise
CVE Liste
- CVE-2015-0992 high
- CVE-2015-0991 high
- CVE-2015-0976 high
- CVE-2015-0995 high
- CVE-2015-0994 high
- CVE-2015-0993 high
Mehr erfahren
Informieren Sie sich über die Statistiken der in Ihrer Region verbreiteten Sicherheitslücken statistics.securelist.com
Sie haben einen Fehler in der Beschreibung der Schwachstelle gefunden? Mitteilen!