Vulnerability record · CVE-2022-35869 · published 25 July 2022
CVE-2022-35869: Inductive Automation Ignition gateway authentication bypass
Inductiveautomation · Ignition
Ignition 8.1.15 (b2022030114) contains an authentication bypass in com.inductiveautomation.ignition.gateway.web.pages, where functionality is reachable without proper authentication. The flaw was reported through ZDI (ZDI-CAN-17211) and rated CVSS 3.1 9.8 critical, so it matters for any internet- or network-exposed Ignition gateway.
Description
This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within com.inductiveautomation.ignition.gateway.web.pages. The issue results from the lack of proper authentication prior to access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-17211.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required and a very high EPSS percentile makes this a top remediation priority despite no KEV listing.
What it is
Ignition 8.1.15 (b2022030114) contains an authentication bypass in com.inductiveautomation.ignition.gateway.web.pages, where functionality is reachable without proper authentication. The flaw was reported through ZDI (ZDI-CAN-17211) and rated CVSS 3.1 9.8 critical, so it matters for any internet- or network-exposed Ignition gateway.
Impact
An unauthenticated attacker can bypass authentication and reach gateway functionality, with CVSS indicating high confidentiality, integrity and availability impact. Full compromise of the gateway is possible depending on what the reachable pages expose.
Attack surface
Reachable over the network via the Ignition gateway web interface (AV:N, AC:L, PR:N, UI:N); no authentication and no user interaction are required. The description does not name the specific endpoint or path.
Exploitation
Not listed in CISA KEV and no ransomware use documented, but EPSS is 0.60292 (99.1st percentile), indicating high predicted exploitation likelihood; references are vendor and ZDI advisories only, with no public exploit detail in the record.
What to do
- Upgrade Ignition to a fixed release per the vendor advisory; 8.1.15 (b2022030114) is the affected build named in the record.
- Restrict network access to the Ignition gateway web interface to trusted hosts; do not expose it directly to the internet.
- Place the gateway behind a reverse proxy or VPN with authentication and allowlisting where feasible.
- Review gateway logs and configuration for unauthorized page access or changes, and rotate credentials if compromise is suspected.
Detection
- Alert on requests to Ignition gateway web pages that succeed without a prior authenticated session.
- Monitor gateway and web server logs for anomalous access to com.inductiveautomation.ignition.gateway.web.pages endpoints from unexpected source IPs.
- Baseline normal gateway page access patterns and flag new or rare user agents and source addresses.
- Watch for configuration or project changes made outside normal administrative sessions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.inductiveautomation.com/hc/en-us/articles/7625759776653-Regarding-Pwn2Own-2022-Vulnerabilities | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-22-1016/ | Third Party AdvisoryVDB Entry |
| https://support.inductiveautomation.com/hc/en-us/articles/7625759776653-Regarding-Pwn2Own-2022-Vulnerabilities | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-22-1016/ | Third Party AdvisoryVDB Entry |
Track CVE-2022-35869 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-35869), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.