CVE-2022-1704: Inductiveautomation Ignition

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

Due to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a XXE attack while restoring the backup.

Affected products

  • Inductiveautomation Ignition: from 7.9.0, before 7.9.21 (fixed in 7.9.21); from 8.1.0, before 8.1.8 (fixed in 8.1.8)

Published 2022-08-05. Last modified 2026-06-17.