CVE-2020-10641
EUVD-2020-308928.04.2020, 19:15
An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This results in consuming the entire available hard-disk space on the Ignition 8 Gateway (versions prior to 8.0.10), causing a denial-of-service condition.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| inductiveautomation | ignition_gateway | 8.0 ≤ 𝑥 < 8.0.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-284 - Improper Access ControlThe software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- CWE-306 - Missing Authentication for Critical FunctionThe product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.