Inductive Automation Ignition
Summary
A vulnerability in Inductive Automation Ignition versions 8.1.53 and earlier allows any authenticated user to create projects due to a blank "Create Project Role(s)" setting. This could be exploited if the user can execute gateway scripts. Newer versions restrict project creation to Designer sessions.
IFF Assessment
The vulnerability allows unauthenticated users to create projects, which is a direct security risk for defenders.
Severity
The CVSS score of 8.8 indicates a high severity vulnerability. Exploitation is possible by any authenticated user if they can execute gateway scripts, leading to the unauthorized creation of projects, which impacts integrity and potentially availability.
Defender Context
Defenders should ensure that their Inductive Automation Ignition systems are updated to version 8.1.54 or later, or alternatively, ensure the "Create Project Role(s)" setting is properly configured. This vulnerability highlights the importance of scrutinizing default configurations and ensuring least privilege principles are applied, especially in critical infrastructure environments.