CVE-2022-36126 Information

Description

An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. The ScriptInvoke function allows remote attackers to execute arbitrary code by supplying a Python script.

Reference

https://support.inductiveautomation.com/hc/en-us/articles/7625759776653 https://srcincite.io/advisories/src-2022-0014/ https://github.com/sourceincite/randy

Share on: