Inductive Automation Ignition
Any authenticated user can create projects in Ignition because the default "Create Project Role(s)" setting is blank. This allows users without authorization to create, modify, or inject malicious logic into projects that control plant operations. The vulnerability exists in Ignition versions 8.1.53 and earlier. Inductive Automation reports this is a configuration issue, not an access control flaw. Users on 8.1.54 or later have project creation restricted to Designer sessions. Earlier versions can be remediated by populating the "Create Project Role(s)" setting to restrict access to a specific Designer Role.
- Network access to the Ignition gateway web interface (typically port 8088 or custom port)
- Valid user credentials for any account on the Ignition gateway
- Ignition version 8.1.53 or earlier
Patching may require device reboot — plan for process interruption
/api/v1/advisories/19aec30a-6e63-4dce-a669-829cec7dc335Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.