An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. The ScriptInvoke function allows remote attackers to execute arbitrary code by supplying a Python script.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://support.inductiveautomation.com/hc/en-us/articles/7625759776653 | vendor advisory |
https://github.com/sourceincite/randy | third party advisory exploit |
https://srcincite.io/advisories/src-2022-0014/ | third party advisory |