Inductive Automation Ignition
cpe:2.3:a:inductiveautomation:ignition:*:*:*:*:*:*:*
- < 8.3.0
A vulnerability exists in Inductive Automation Ignition Software versions prior to 8.3.0, allowing an unauthenticated API endpoint exposure. This vulnerability could enable an attacker to remotely change the 'forgot password' recovery email address.
Exploitation of this vulnerability could allow an attacker to change the password recovery email address, potentially leading to unauthorized access.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.