CVE-2020-10641

HIGH

Ignition Gateway 8.0-8.0.9 - Unauthenticated Denial of Service via Unprotected Logging Route

Title source: llm
STIX 2.1

Description

An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This results in consuming the entire available hard-disk space on the Ignition 8 Gateway (versions prior to 8.0.10), causing a denial-of-service condition.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://www.us-cert.gov/ics/advisories/icsa-20-112-01

Scores

CVSS v3 7.5
EPSS 0.0128
EPSS Percentile 66.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-284 CWE-306
Status published
Products (1)
inductiveautomation/ignition_gateway 8.0 - 8.0.10
Published Apr 28, 2020
Tracked Since Feb 18, 2026