ZeroHour

Vulnerabilities

34 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-13913
A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious code.

A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious code.

NVD description · AI analysis pending
5.4<1%
  • inductiveautomation ignition
CVE-2023-39475
Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability.

Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ParameterVersionJavaSerializationCodec class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-20290.

NVD description · AI analysis pending
9.8
group max
64%
  • inductiveautomation ignition
CVE-2022-1704
Due to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a XXE attack

Due to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a XXE attack while restoring the backup.

NVD description · AI analysis pending
9.8<1%
  • inductiveautomation ignition
CVE-2022-35869
+4 in the same advisory: …35870 …35871 …35873 …35872
This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114).

This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within com.inductiveautomation.ignition.gateway.web.pages. The issue results from the lack of proper authentication prior to access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-17211.

NVD description · AI analysis pending
9.8
group max
60%
  • inductiveautomation ignition
CVE-2022-1264
The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code.

The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code.

NVD description · AI analysis pending
8.8<1%
  • inductiveautomation ignition
CVE-2022-36126
An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17.

An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. The ScriptInvoke function allows remote attackers to execute arbitrary code by supplying a Python script.

NVD description · AI analysis pending
7.23% PoC
  • inductiveautomation ignition
CVE-2022-35890
An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17.

An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. Designer and Vision Client Session IDs are mishandled. An attacker can determine which session IDs were generated in the past and then hijack sessions assigned to these IDs via Randy.

NVD description · AI analysis pending
9.82% PoC
  • inductiveautomation ignition
CVE-2020-14479
Sensitive information can be obtained through the handling of serialized data.

Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server

NVD description · AI analysis pending
5.3<1%
  • inductiveautomation ignition
CVE-2020-14520
The affected product is vulnerable to an information leak, which may allow an attacker to obtain sensitive information on the Ignition 8 (all versions prior to

The affected product is vulnerable to an information leak, which may allow an attacker to obtain sensitive information on the Ignition 8 (all versions prior to 8.0.13).

NVD description · AI analysis pending
7.51%
  • inductiveautomation ignition gateway
CVE-2020-10644
+2 in the same advisory: …12004 …12000
The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions pr

The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14), allowing an attacker to obtain sensitive information.

NVD description · AI analysis pending
7.520%
  • inductiveautomation ignition gateway
CVE-2020-10641
An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication.

An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This results in consuming the entire available hard-disk space on the Ignition 8 Gateway (versions prior to 8.0.10), causing a denial-of-service condition.

NVD description · AI analysis pending
7.51%
  • inductiveautomation ignition gateway