← Back to browse · API

CVE-2023-38124

Severity
HIGH
CVSS
7.2
EPSS
0.59609
Risk score
49.66
CISA KEV
No
PoC
No
Published
2024-05-03
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2023-41950, GHSA-FJ6X-XHQ4-HQ99
Products
Inductive Automation:Ignition 8.1.24
Sources
euvd EUVD-2023-41950

Description

Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The specific flaw exists within the Ignition Gateway server. The issue results from the exposure of a dangerous function. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-20541.

References