← Back to browse · API

CVE-2022-35871

Severity
HIGH
CVSS
8.1
EPSS
0.39194
Risk score
46.12
CISA KEV
No
PoC
No
Published
2022-07-25
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2022-38744, GHSA-R5VJ-595H-W86Q
Products
Inductive Automation:Ignition 8.1.15 (b2022030114)
Sources
euvd EUVD-2022-38744

Description

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within the authenticateAdSso method. The issue results from the lack of authentication prior to allowing the execution of python code. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-17206.

References