Industry Automation Ignition XSS Vulnerability (CVE-2015-0976)
Release date:
Updated on:
Affected Systems:
Inductive Automation Ignition
Description:
CVE (CAN) ID: CVE-2015-0976
Ignition is a new FactoryPMI, human-machine interface, and SCADA product provided by Inductive Automation.
Ignition has a security vulnerability. Attackers can exploit this vulnerability to execute malicious content in vulnerable Web applications. The server reads data directly from the HTTP request and returns the data in the HTTP response.
<* Source: Evgeny Druzhinin
Alexey Osipov
Ilya Karpov
Link: https://ics-cert.us-cert.gov/advisories/ICSA-15-090-01
*>
Suggestion:
Vendor patch:
Inductive Automation
--------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://www.inductiveautomation.com/downloads/ignition
This article permanently updates the link address: