← back
CVE-2020-10644

CVE-2020-10644

EPSS 20.2%CWE-502
Vexday Risk Score
23Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS EPSS 20.2%KEV nãoPoC Nuclei Metasploit simPatch
Lifecycle
09 Jun 2020Published on NVD
11 Jun 2020Metasploit module available
Recommendation: Plan a near-term fix — a public PoC already exists.
The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14), allowing an attacker to obtain sensitive information.
Affected products
n/a · Ignition 8 Gateway

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →