CVE-2020-14479

MEDIUM

Ignition 7.0.0-7.9.13 - Unauthenticated Sensitive Information Exposure via Serialized Data Handling

Title source: llm
STIX 2.1

Description

Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server

References (1)

Core 1
Core References
Patch, Third Party Advisory, US Government Resource x_refsource_misc
https://www.cisa.gov/uscert/ics/advisories/icsa-20-147-01

Scores

CVSS v3 5.3
EPSS 0.0085
EPSS Percentile 53.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
inductiveautomation/ignition 7.0.0 - 7.9.14
Published Apr 01, 2022
Tracked Since Feb 18, 2026