CVE-2020-12000
09.06.2020, 18:15
The affected product is vulnerable to the handling of serialized data. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14), allowing an attacker to obtain sensitive information.Enginsight
Vendor | Product | Version |
---|---|---|
inductiveautomation | ignition_gateway | 7.2.4.48 ≤ 𝑥 < 7.9.14 |
inductiveautomation | ignition_gateway | 8.0 ≤ 𝑥 < 8.0.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration