An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. Designer and Vision Client Session IDs are mishandled. An attacker can determine which session IDs were generated in the past and then hijack sessions assigned to these IDs via Randy.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-07-15T20:07:28

Updated: 2022-07-15T20:07:28

Reserved: 2022-07-15T00:00:00


Link: CVE-2022-35890

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-07-15T21:15:08.827

Modified: 2022-07-21T14:45:20.123


Link: CVE-2022-35890

JSON object: View

cve-icon Redhat Information

No data.

CWE