Inductive Automation develops industrial control and automation platforms centered on its Ignition product line, which serves as a supervisory control and data acquisition (SCADA) and manufacturing execution system widely deployed in critical infrastructure and factory environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the safety-critical and data-integrity demands of industrial automation software; the recurring exposure centers on deserialization of untrusted data, missing authentication for sensitive functions, exposure of configuration and operational data, path traversal, and cross-site scripting, classes that carry particular weight in networked control systems where authentication bypass and data leakage can cascade into operational disruption. The narrow product portfolio concentrates risk around the Ignition gateway and its associated ecosystem, meaning that a single vulnerability class can affect a large installed base across manufacturing, utility, and process-control deployments. Defenders in industrial and critical-infrastructure sectors should prioritize tracking this vendor's security advisories and apply patches expeditiously to systems exposed to untrusted networks, given the control-plane nature of affected products. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Inductiveautomation over time
Signals from CVEs in this vendor scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-35869CRITICAL This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required | Jul 25, 2022 | 9.8 | 63 | NO | NO |
CVE-2023-39473HIGH Inductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a | May 3, 2024 | 8.8 | 56 | NO | NO |
CVE-2023-50223HIGH Inductive Automation Ignition ExtendedDocumentCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb | May 3, 2024 | 8.8 | 55 | NO | NO |
CVE-2023-50218HIGH Inductive Automation Ignition ModuleInvoke Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co | May 3, 2024 | 8.8 | 54 | NO | NO |
CVE-2023-38124HIGH Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exec | May 3, 2024 | 8.8 | 54 | NO | NO |
CVE-2022-35871HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required | Jul 25, 2022 | 7.8 | 48 | NO | NO |
CVE-2022-35870HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Although authentication is req | Jul 25, 2022 | 7.8 | 48 | NO | NO |
CVE-2020-12004HIGH The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14) | Jun 9, 2020 | 7.5 | 42 | NO | YES |
CVE-2020-10644HIGH The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions prior to 8.0.10) and I | Jun 9, 2020 | 7.5 | 38 | NO | YES |
CVE-2023-39475CRITICAL Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attacke | May 3, 2024 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (40 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inductiveautomation.
Media articles that mention a CVE ID that affects a product developed by Inductiveautomation — matched by CVE ID, not by vendor name.