Inductive Automation Ignition Remote Information Disclosure Vulnerability
BID:49447
Info
Inductive Automation Ignition Remote Information Disclosure Vulnerability
| Bugtraq ID: | 49447 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 19 2011 12:00AM |
| Updated: | Aug 19 2011 12:00AM |
| Credit: | Rubén Santamarta |
| Vulnerable: |
Inductive Automation Ignition 7.2.8.177 Inductive Automation Ignition 7.2.8.176 |
| Not Vulnerable: |
Inductive Automation Ignition 7.2.8.178 |
Discussion
Inductive Automation Ignition Remote Information Disclosure Vulnerability
Ignition is prone to an information-disclosure vulnerability.
Exploiting this issue could allow an attacker to gain access to potentially sensitive information. Information obtained may aid in further attacks.
Versions prior to Ignition 7.2.8.178 are vulnerable.
Ignition is prone to an information-disclosure vulnerability.
Exploiting this issue could allow an attacker to gain access to potentially sensitive information. Information obtained may aid in further attacks.
Versions prior to Ignition 7.2.8.178 are vulnerable.
Exploit / POC
Inductive Automation Ignition Remote Information Disclosure Vulnerability
Attackers can use readily available tools or a browser to exploit this issue.
Attackers can use readily available tools or a browser to exploit this issue.
Solution / Fix
Inductive Automation Ignition Remote Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Inductive Automation Ignition Remote Information Disclosure Vulnerability
References:
References:
- ICSA-11-231-01�??INDUCTIVE AUTOMATION IGNITION INFORMATION DISCLOSURE VULNERABILIT (ICS-CERT)
- Product Homepage (Inductive Automation)