Skip to main content
EPSS 0.2%top 84%

CVE-2025-13911: CWE-250 in Inductive Automation Ignition

0
Medium
VulnerabilityCVE-2025-13911cvecve-2025-13911cwe-250gcve
Published: 12/18/2025 (12/18/2025, 20:24:30 UTC)
Source: CVE Database V5
Vendor/Project: Inductive Automation
Product: Ignition

Description

Ignition by Inductive Automation, when installed with default OS service account settings, may expose the host system to an elevated code execution risk via the gateway backup restore functionality. An authenticated user with Gateway Administrator privileges can import a malicious gateway backup (.gwbk) file containing crafted project resources, scripts, or modules, resulting in code execution on the host system. This affects both Windows and Linux installations. On Windows, default installations often run the Ignition service as NT AUTHORITY\SYSTEM, resulting in code execution with full local system privileges. On Linux, default installations commonly run the Ignition service as root or with elevated privileges. Specific privilege level depends on installation configuration.

CVSS v3.1

Score 6.4medium

Attack Vector
Adjacent Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected software

GitHub Actionsmore threats →ai
inductiveautomation/ignition
pkg:github/inductiveautomation/ignition
Affected versions
<8.2.0 >=8.1.0<8.4.0 >=8.3.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 12/25/2025, 21:16:12 UTC

Technical Analysis

CVE-2025-13911 is a vulnerability classified under CWE-250 (Execution with Unnecessary Privileges) affecting Inductive Automation's Ignition SCADA software versions 8.1.x and 8.3.x. The core issue stems from the Ignition Gateway process running with SYSTEM-level permissions on Windows, combined with insufficient security controls restricting which Python libraries can be imported and executed within the embedded scripting environment. Authenticated administrators can upload malicious project files containing Python scripts that leverage bind shell capabilities or alternative code execution techniques. These scripts execute with the same elevated privileges as the Ignition service account, effectively granting attackers SYSTEM-level access to the host machine. The vulnerability requires an authenticated user with administrative privileges within Ignition, no additional user interaction is needed once the malicious project is uploaded. The lack of proper sandboxing or library import restrictions in the Python scripting environment enables attackers to execute arbitrary code with high privileges. Although no public exploits have been reported, the potential for full system compromise in industrial control environments is significant. The vulnerability was published on December 18, 2025, with a CVSS v3.1 score of 6.4, reflecting medium severity due to the requirement for high privileges and network attack vector. The vulnerability highlights the risk of excessive permissions and inadequate scripting environment controls in critical infrastructure software.

Potential Impact

For European organizations, especially those operating in industrial automation, manufacturing, energy, and critical infrastructure sectors, this vulnerability poses a substantial risk. Exploitation could lead to full system compromise of the Ignition Gateway host, enabling attackers to manipulate automation processes, disrupt operations, exfiltrate sensitive data, or deploy ransomware. The SYSTEM-level privileges allow attackers to bypass many security controls, potentially affecting the confidentiality, integrity, and availability of industrial control systems. Given Ignition's widespread use in SCADA environments across Europe, successful exploitation could cause operational downtime, safety hazards, and significant financial and reputational damage. The requirement for authenticated administrator access somewhat limits the attack surface but insider threats or compromised credentials could facilitate exploitation. The vulnerability also raises concerns about supply chain security and the trustworthiness of uploaded project files. European organizations must consider the potential cascading effects on interconnected industrial networks and the broader impact on national critical infrastructure resilience.

Mitigation Recommendations

1. Restrict Ignition administrator access strictly to trusted personnel and enforce strong multi-factor authentication to reduce the risk of credential compromise. 2. Implement rigorous validation and scanning of all uploaded project files to detect and block malicious Python scripts or unusual library imports. 3. Run the Ignition Gateway service under a least-privilege account rather than SYSTEM-level permissions where feasible, to limit the impact of code execution. 4. Employ application whitelisting and endpoint detection solutions on hosts running Ignition to monitor and block unauthorized script execution or network connections initiated by the Ignition process. 5. Regularly audit and review Python scripting usage within Ignition projects to identify and remove unnecessary or potentially risky scripts. 6. Keep Ignition software up to date and monitor vendor advisories for patches or security enhancements addressing this vulnerability. 7. Segment industrial networks to isolate SCADA systems from broader enterprise networks, reducing lateral movement opportunities. 8. Conduct security awareness training for administrators on the risks of uploading untrusted project files and the importance of secure scripting practices.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
icscert
Date Reserved
2025-12-02T17:14:36.352Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 69446a7c4eb3efac36a9617d

Added to database: 12/18/2025, 20:56:28 UTC

Last enriched: 12/25/2025, 21:16:12 UTC

Last updated: 09/10/2026, 19:36:49 UTC

Views: 589

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses