← Vulnerability feed

Vulnerability record · CVE-2022-35869 · published 25 July 2022

CVE-2022-35869: Inductive Automation Ignition gateway authentication bypass

Inductiveautomation · Ignition

Ignition 8.1.15 (b2022030114) contains an authentication bypass in com.inductiveautomation.ignition.gateway.web.pages, where functionality is reachable without proper authentication. The flaw was reported through ZDI (ZDI-CAN-17211) and rated CVSS 3.1 9.8 critical, so it matters for any internet- or network-exposed Ignition gateway.

9.8 CVSS 3.1 Critical EPSS 60% · top 0.9% CWE-288 · Authentication bypass via alternate path
9.8CVSS 3.1 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within com.inductiveautomation.ignition.gateway.web.pages. The issue results from the lack of proper authentication prior to access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-17211.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or user interaction required and a very high EPSS percentile makes this a top remediation priority despite no KEV listing.

What it is

Ignition 8.1.15 (b2022030114) contains an authentication bypass in com.inductiveautomation.ignition.gateway.web.pages, where functionality is reachable without proper authentication. The flaw was reported through ZDI (ZDI-CAN-17211) and rated CVSS 3.1 9.8 critical, so it matters for any internet- or network-exposed Ignition gateway.

Impact

An unauthenticated attacker can bypass authentication and reach gateway functionality, with CVSS indicating high confidentiality, integrity and availability impact. Full compromise of the gateway is possible depending on what the reachable pages expose.

Attack surface

Reachable over the network via the Ignition gateway web interface (AV:N, AC:L, PR:N, UI:N); no authentication and no user interaction are required. The description does not name the specific endpoint or path.

Exploitation

Not listed in CISA KEV and no ransomware use documented, but EPSS is 0.60292 (99.1st percentile), indicating high predicted exploitation likelihood; references are vendor and ZDI advisories only, with no public exploit detail in the record.

What to do

  • Upgrade Ignition to a fixed release per the vendor advisory; 8.1.15 (b2022030114) is the affected build named in the record.
  • Restrict network access to the Ignition gateway web interface to trusted hosts; do not expose it directly to the internet.
  • Place the gateway behind a reverse proxy or VPN with authentication and allowlisting where feasible.
  • Review gateway logs and configuration for unauthorized page access or changes, and rotate credentials if compromise is suspected.

Detection

  • Alert on requests to Ignition gateway web pages that succeed without a prior authenticated session.
  • Monitor gateway and web server logs for anomalous access to com.inductiveautomation.ignition.gateway.web.pages endpoints from unexpected source IPs.
  • Baseline normal gateway page access patterns and flag new or rare user agents and source addresses.
  • Watch for configuration or project changes made outside normal administrative sessions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-35869 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-39475Inductive Automation Ignition Java deserialization RCEInductive Automation Ignition fails to validate user-supplied data in the ParameterVersionJavaSerializationCodec class, allowing deserialization of u…EPSS 64%analysed9.8CVE-2023-39476Inductiveautomation ignition deserialization of untrusted data vulnerabilityInductive Automation Ignition JavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows…EPSS 2.2%9.8CVE-2022-1704Inductiveautomation ignition xml external entity (xxe) vulnerabilityDue to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a …EPSS 0.96%9.8CVE-2022-35890Inductiveautomation ignition incorrect authorization vulnerabilityAn issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. Designer and Vision Client Session IDs are mishandled. …EPSS 2.0%9.0CVE-2023-38121Inductiveautomation ignition cross-site scripting vulnerabilityInductive Automation Ignition OPC UA Quick Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attacker…EPSS 1.2%8.8CVE-2023-50232Inductiveautomation ignition argument injection vulnerabilityInductive Automation Ignition getParams Argument Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute…EPSS 1.4%8.8CVE-2023-50233Inductiveautomation ignition path traversal vulnerabilityInductive Automation Ignition getJavaExecutable Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers t…EPSS 2.1%8.8CVE-2023-50220Inductiveautomation ignition deserialization of untrusted data vulnerabilityInductive Automation Ignition Base64Element Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote a…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2022-35869), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.