Description
A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious code.
References (3)
Core 3
Core References
Third Party Advisory
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-071-06.json
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-06
Scores
CVSS v3
6.3
EPSS
0.0001
EPSS Percentile
0.9%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-502
Status
published
Products (2)
Inductive Automation/Ignition Software
< 8.3.0
Inductive Automation/Ignition Software
8.3.0
Published
Mar 12, 2026
Tracked Since
Mar 13, 2026