Ignition
Vendor:
First CVE: Apr 3, 2015 · Active for 11 years
35
Total CVEs
More Total CVEs than 96% of tracked products
8.8
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ignition over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 3, 2015
11 years ago
Most Recent CVE
Mar 12, 2026
136 days ago
CVE Severity & Scoring
Ignition35 CVEs
23%
57%
17%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (11.4%)
Network24 (68.6%)
Unknown6 (17.1%)
Physical0 (0.0%)
Adjacent Network1 (2.9%)
Attack Complexity
Low29 (82.9%)
High0 (0.0%)
Unknown6 (17.1%)
User Interaction
None18 (51.4%)
Unknown6 (17.1%)
Required11 (31.4%)
Privileges Required
Low9 (25.7%)
High3 (8.6%)
None17 (48.6%)
Unknown6 (17.1%)
Top CVEs
Signals from CVEs in this product scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-39475CRITICAL Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attacke | May 3, 2024 | 9.8 | 63 | NO | NO |
CVE-2022-35869CRITICAL This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required | Jul 25, 2022 | 9.8 | 63 | NO | NO |
CVE-2023-39473HIGH Inductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a | May 3, 2024 | 8.8 | 56 | NO | NO |
CVE-2023-50223HIGH Inductive Automation Ignition ExtendedDocumentCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb | May 3, 2024 | 8.8 | 55 | NO | NO |
CVE-2023-50218HIGH Inductive Automation Ignition ModuleInvoke Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co | May 3, 2024 | 8.8 | 54 | NO | NO |
CVE-2023-38124HIGH Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exec | May 3, 2024 | 8.8 | 54 | NO | NO |
CVE-2022-35871HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required | Jul 25, 2022 | 7.8 | 48 | NO | NO |
CVE-2022-35870HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Although authentication is req | Jul 25, 2022 | 7.8 | 48 | NO | NO |
CVE-2023-50220HIGH Inductive Automation Ignition Base64Element Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c | May 3, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-50222HIGH Inductive Automation Ignition ResponseParser Notification Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu | May 3, 2024 | 8.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (35 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (35 CVEs).
Media Mentions
Signals from CVEs in this product scope (35 CVEs).
Top CNAs Publishing CVEs For Ignition
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.1.15 | 5 | 8.2 | 28.8% | 0 | 0 |
| 7.7.2 | 6 | 4.5 | 1.2% | 0 | 0 |