CVE-2025-13911: CWE-250 in Inductive Automation Ignition
Ignition by Inductive Automation, when installed with default OS service account settings, may expose the host system to an elevated code execution risk via the gateway backup restore functionality. An authenticated user with Gateway Administrator privileges can import a malicious gateway backup (.gwbk) file containing crafted project resources, scripts, or modules, resulting in code execution on the host system. This affects both Windows and Linux installations. On Windows, default installations often run the Ignition service as NT AUTHORITY\SYSTEM, resulting in code execution with full local system privileges. On Linux, default installations commonly run the Ignition service as root or with elevated privileges. Specific privilege level depends on installation configuration.
AI Analysis
Technical Summary
CVE-2025-13911 is a vulnerability classified under CWE-250 (Execution with Unnecessary Privileges) affecting Inductive Automation's Ignition SCADA software versions 8.1.x and 8.3.x. The core issue stems from the Ignition Gateway process running with SYSTEM-level permissions on Windows, combined with insufficient security controls restricting which Python libraries can be imported and executed within the embedded scripting environment. Authenticated administrators can upload malicious project files containing Python scripts that leverage bind shell capabilities or alternative code execution techniques. These scripts execute with the same elevated privileges as the Ignition service account, effectively granting attackers SYSTEM-level access to the host machine. The vulnerability requires an authenticated user with administrative privileges within Ignition, no additional user interaction is needed once the malicious project is uploaded. The lack of proper sandboxing or library import restrictions in the Python scripting environment enables attackers to execute arbitrary code with high privileges. Although no public exploits have been reported, the potential for full system compromise in industrial control environments is significant. The vulnerability was published on December 18, 2025, with a CVSS v3.1 score of 6.4, reflecting medium severity due to the requirement for high privileges and network attack vector. The vulnerability highlights the risk of excessive permissions and inadequate scripting environment controls in critical infrastructure software.
Potential Impact
For European organizations, especially those operating in industrial automation, manufacturing, energy, and critical infrastructure sectors, this vulnerability poses a substantial risk. Exploitation could lead to full system compromise of the Ignition Gateway host, enabling attackers to manipulate automation processes, disrupt operations, exfiltrate sensitive data, or deploy ransomware. The SYSTEM-level privileges allow attackers to bypass many security controls, potentially affecting the confidentiality, integrity, and availability of industrial control systems. Given Ignition's widespread use in SCADA environments across Europe, successful exploitation could cause operational downtime, safety hazards, and significant financial and reputational damage. The requirement for authenticated administrator access somewhat limits the attack surface but insider threats or compromised credentials could facilitate exploitation. The vulnerability also raises concerns about supply chain security and the trustworthiness of uploaded project files. European organizations must consider the potential cascading effects on interconnected industrial networks and the broader impact on national critical infrastructure resilience.
Mitigation Recommendations
1. Restrict Ignition administrator access strictly to trusted personnel and enforce strong multi-factor authentication to reduce the risk of credential compromise. 2. Implement rigorous validation and scanning of all uploaded project files to detect and block malicious Python scripts or unusual library imports. 3. Run the Ignition Gateway service under a least-privilege account rather than SYSTEM-level permissions where feasible, to limit the impact of code execution. 4. Employ application whitelisting and endpoint detection solutions on hosts running Ignition to monitor and block unauthorized script execution or network connections initiated by the Ignition process. 5. Regularly audit and review Python scripting usage within Ignition projects to identify and remove unnecessary or potentially risky scripts. 6. Keep Ignition software up to date and monitor vendor advisories for patches or security enhancements addressing this vulnerability. 7. Segment industrial networks to isolate SCADA systems from broader enterprise networks, reducing lateral movement opportunities. 8. Conduct security awareness training for administrators on the risks of uploading untrusted project files and the importance of secure scripting practices.
Affected Countries
Germany, France, Italy, United Kingdom, Netherlands, Belgium, Sweden, Poland
CVE-2025-13911: CWE-250 in Inductive Automation Ignition
Description
Ignition by Inductive Automation, when installed with default OS service account settings, may expose the host system to an elevated code execution risk via the gateway backup restore functionality. An authenticated user with Gateway Administrator privileges can import a malicious gateway backup (.gwbk) file containing crafted project resources, scripts, or modules, resulting in code execution on the host system. This affects both Windows and Linux installations. On Windows, default installations often run the Ignition service as NT AUTHORITY\SYSTEM, resulting in code execution with full local system privileges. On Linux, default installations commonly run the Ignition service as root or with elevated privileges. Specific privilege level depends on installation configuration.
CVSS v3.1
Score 6.4medium
Affected software
pkg:github/inductiveautomation/ignitionRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-13911 is a vulnerability classified under CWE-250 (Execution with Unnecessary Privileges) affecting Inductive Automation's Ignition SCADA software versions 8.1.x and 8.3.x. The core issue stems from the Ignition Gateway process running with SYSTEM-level permissions on Windows, combined with insufficient security controls restricting which Python libraries can be imported and executed within the embedded scripting environment. Authenticated administrators can upload malicious project files containing Python scripts that leverage bind shell capabilities or alternative code execution techniques. These scripts execute with the same elevated privileges as the Ignition service account, effectively granting attackers SYSTEM-level access to the host machine. The vulnerability requires an authenticated user with administrative privileges within Ignition, no additional user interaction is needed once the malicious project is uploaded. The lack of proper sandboxing or library import restrictions in the Python scripting environment enables attackers to execute arbitrary code with high privileges. Although no public exploits have been reported, the potential for full system compromise in industrial control environments is significant. The vulnerability was published on December 18, 2025, with a CVSS v3.1 score of 6.4, reflecting medium severity due to the requirement for high privileges and network attack vector. The vulnerability highlights the risk of excessive permissions and inadequate scripting environment controls in critical infrastructure software.
Potential Impact
For European organizations, especially those operating in industrial automation, manufacturing, energy, and critical infrastructure sectors, this vulnerability poses a substantial risk. Exploitation could lead to full system compromise of the Ignition Gateway host, enabling attackers to manipulate automation processes, disrupt operations, exfiltrate sensitive data, or deploy ransomware. The SYSTEM-level privileges allow attackers to bypass many security controls, potentially affecting the confidentiality, integrity, and availability of industrial control systems. Given Ignition's widespread use in SCADA environments across Europe, successful exploitation could cause operational downtime, safety hazards, and significant financial and reputational damage. The requirement for authenticated administrator access somewhat limits the attack surface but insider threats or compromised credentials could facilitate exploitation. The vulnerability also raises concerns about supply chain security and the trustworthiness of uploaded project files. European organizations must consider the potential cascading effects on interconnected industrial networks and the broader impact on national critical infrastructure resilience.
Mitigation Recommendations
1. Restrict Ignition administrator access strictly to trusted personnel and enforce strong multi-factor authentication to reduce the risk of credential compromise. 2. Implement rigorous validation and scanning of all uploaded project files to detect and block malicious Python scripts or unusual library imports. 3. Run the Ignition Gateway service under a least-privilege account rather than SYSTEM-level permissions where feasible, to limit the impact of code execution. 4. Employ application whitelisting and endpoint detection solutions on hosts running Ignition to monitor and block unauthorized script execution or network connections initiated by the Ignition process. 5. Regularly audit and review Python scripting usage within Ignition projects to identify and remove unnecessary or potentially risky scripts. 6. Keep Ignition software up to date and monitor vendor advisories for patches or security enhancements addressing this vulnerability. 7. Segment industrial networks to isolate SCADA systems from broader enterprise networks, reducing lateral movement opportunities. 8. Conduct security awareness training for administrators on the risks of uploading untrusted project files and the importance of secure scripting practices.
Affected Countries
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- icscert
- Date Reserved
- 2025-12-02T17:14:36.352Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 69446a7c4eb3efac36a9617d
Added to database: 12/18/2025, 20:56:28 UTC
Last enriched: 12/25/2025, 21:16:12 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 589
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.