Описание
An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. Designer and Vision Client Session IDs are mishandled. An attacker can determine which session IDs were generated in the past and then hijack sessions assigned to these IDs via Randy.
Ссылки
- ExploitThird Party Advisory
- Vendor Advisory
- ExploitThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.9.20 (исключая)Версия от 8.0.1 (включая) до 8.1.17 (исключая)
Одно из
cpe:2.3:a:inductiveautomation:ignition:*:*:*:*:*:*:*:*
cpe:2.3:a:inductiveautomation:ignition:*:*:*:*:*:*:*:*
EPSS
Процентиль: 76%
0.00985
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. Designer and Vision Client Session IDs are mishandled. An attacker can determine which session IDs were generated in the past and then hijack sessions assigned to these IDs via Randy.
EPSS
Процентиль: 76%
0.00985
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-863