CVE-2022-35871 is a critical remote code execution (RCE) vulnerability affecting Inductive Automation Ignition version 8.1.15 (b2022030114). This flaw, stemming from a lack of authentication in the authenticateAdSso method, allows unauthenticated remote attackers to execute arbitrary Python code. Successful exploitation grants SYSTEM-level privileges, posing a high risk to confidentiality, integrity, and availability. While not currently listed in CISA KEV, there is significant community discussion and GitHub activity, indicating potential for public exploit development.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.1.15CPE matchmatch criteria | cpe:2.3:a:inductiveautomation:ignition:8.1.15:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.