CVE-2020-12004
CVE-2020-12004
Vexday Risk Score
23Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 13.6%KEV nãoPoC —Nuclei —Metasploit simPatch —
Lifecycle
09 Jun 2020Published on NVD
11 Jun 2020Metasploit module available
Recommendation: Plan a near-term fix — a public PoC already exists.
The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14), allowing an attacker to obtain sensitive information.
Affected products
n/a · Ignition 8 GatewayWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →