Incorrect default permissions in Inductive Automation Ignition 8.1 allow unauthorized project creation
AI analysis
Ignition 8.1.53 and earlier shipped with the Gateway's "Create Project Role(s)" setting blank, so the role restriction it was meant to enforce was not applied (CWE-276, incorrect default permissions). An attacker needs network access and a low-privilege authenticated account that can execute gateway scripts; with those, a project-creation request against the Gateway succeeds without requiring Designer access. By creating a project, the attacker can gain high-impact access to the gateway per its CVSS 4.0 score of 8.7 (high confidentiality, integrity, and availability impact), making this useful as a foothold in OT/SCADA environments. All Ignition 8.1 deployments at or below 8.1.53 are affected; 8.1.54 restricts project creation to Designer sessions and the 8.3 series is not affected. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at 0.5% (42nd percentile).
What to do: Upgrade Ignition 8.1 to 8.1.54 or later, which restricts project creation to Designer sessions. As an interim mitigation, set the Gateway "Create Project Role(s)" setting to a restricted role and review which authenticated users have gateway script execution rights. Audit existing projects for any unexpected creations made by non-Designer users.
Affected
| Inductive Automation Ignition | 8.1 releases through 8.1.53 (fixed in 8.1.54; 8.3 series not affected) |
Estimated exposure
large≈10,000–100,000 systems (tens of thousands of internet-exposed Ignition gateways, with a larger total 8.1 installed base) — Public internet-wide scans (e.g., Shodan/Censys) typically show tens of thousands of exposed Inductive Automation Ignition gateways, and because every 8.1 release up to 8.1.53 is affected, all pre-8.1.54 installations are in scope, though…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.