CVE-2025-13911 (GCVE-0-2025-13911)
Vulnerability from cvelistv5
Published
2025-12-18 20:24
Modified
2026-08-27 23:30
CWE
Summary
Ignition by Inductive Automation, when installed with default OS service account settings, may expose the host system to an elevated code execution risk via the gateway backup restore functionality. An authenticated user with Gateway Administrator privileges can import a malicious gateway backup (.gwbk) file containing crafted project resources, scripts, or modules, resulting in code execution on the host system. This affects both Windows and Linux installations. On Windows, default installations often run the Ignition service as NT AUTHORITY\SYSTEM, resulting in code execution with full local system privileges. On Linux, default installations commonly run the Ignition service as root or with elevated privileges. Specific privilege level depends on installation configuration.
Impacted products
Vendor Product Version
Inductive Automation Ignition Version: 8.1.x
Version: 8.3.x
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-13911",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-12-18T20:44:32.471219Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-12-18T20:45:07.276Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Ignition",
          "vendor": "Inductive Automation",
          "versions": [
            {
              "status": "affected",
              "version": "8.1.x"
            },
            {
              "status": "affected",
              "version": "8.3.x"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Momen Eldawakhly of Samurai Digital Security Ltd reported this vulnerability to CISA."
        },
        {
          "lang": "en",
          "type": "finder",
          "value": "Ethan Thomason of CedarTech reported this vulnerability to CISA."
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Ignition by Inductive Automation, when installed with default OS service\n account settings, may expose the host system to an elevated code \nexecution risk via the gateway backup restore functionality. An \nauthenticated user with Gateway Administrator privileges can import a \nmalicious gateway backup (.gwbk) file containing crafted project \nresources, scripts, or modules, resulting in code execution on the host \nsystem. This affects both Windows and Linux installations. On Windows, \ndefault installations often run the Ignition service as NT \nAUTHORITY\\SYSTEM, resulting in code execution with full local system \nprivileges. On Linux, default installations commonly run the Ignition \nservice as root or with elevated privileges. Specific privilege level \ndepends on installation configuration."
            }
          ],
          "value": "Ignition by Inductive Automation, when installed with default OS service\n account settings, may expose the host system to an elevated code \nexecution risk via the gateway backup restore functionality. An \nauthenticated user with Gateway Administrator privileges can import a \nmalicious gateway backup (.gwbk) file containing crafted project \nresources, scripts, or modules, resulting in code execution on the host \nsystem. This affects both Windows and Linux installations. On Windows, \ndefault installations often run the Ignition service as NT \nAUTHORITY\\SYSTEM, resulting in code execution with full local system \nprivileges. On Linux, default installations commonly run the Ignition \nservice as root or with elevated privileges. Specific privilege level \ndepends on installation configuration."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "NONE",
            "attackVector": "ADJACENT",
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-250",
              "description": "CWE-250",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-27T23:30:14.119Z",
        "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "shortName": "icscert"
      },
      "references": [
        {
          "url": "https://security.inductiveautomation.com/"
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-352-01"
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-352-01.json"
        }
      ],
      "source": {
        "advisory": "ICSA-25-352-01",
        "discovery": "EXTERNAL"
      },
      "title": "Inductive Automation Ignition Execution with Unnecessary Privileges",
      "workarounds": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eInductive Automation encourages users to do the following in order to reduce the risk of this vulnerability:\u003c/p\u003e\u003col\u003e\u003cli\u003eCreate a new dedicated local Windows account that will be used \nexclusively for the Ignition service (e.g. svc-ign) (this should not be a\n domain account).\u003c/li\u003e\u003cli\u003e\nRemove all group memberships from the service account (including Users and Administrators).\u003c/li\u003e\u003cli\u003eAdd to security policy to log in as a service.\u003c/li\u003e\u003cli\u003eAdd to \u201cDeny log on locally\u201d security policy.\u003c/li\u003e\u003cli\u003e\nProvide full read/write access only to the Ignition installation directory for the service account created in step 1.\u003c/li\u003e\u003cli\u003e\nAdd read/write permissions to other directories in the local filesystem \nas needed (e.g: if configured to use optional Enterprise Administration \nModule to write automated backups to the file system).\u003c/li\u003e\u003cli\u003e\nSet deny access settings for service account on other directories not needed by the Ignition service.\u003c/li\u003e\u003cli\u003e\nSpecifically the C:\\Windows, C:\\Users, and directories for any other \napplications in the Program Files or Program Files (x86) directories.\u003c/li\u003e\u003cli\u003e\nUse java param to change temp directory to a location within the \nIgnition install directory so the Users folder can be denied access to \nthe Ignition service account.\u003c/li\u003e\u003cli\u003e\nRestrict project imports to verified and trusted sources only, ideally using checksums or digital signatures.\u003c/li\u003e\u003cli\u003e\nUse multiple environments (e.g. Dev, Test, Prod) with a staging workflow\n so that new data is never introduced directly to Production \nenvironments. See Ignition Deployment Best Practices.\u003c/li\u003e\u003cli\u003e\nWhen feasible, segment or isolate Ignition gateways from corporate resources and Windows Domains.\u003c/li\u003e\u003cli\u003e\nThe Ignition service account or AD server object should never need \nWindows Domain or Windows Active Directory privileges. This would only \nbe needed if an Asset Owners IT or OT department uses this for \nmanagement outside Ignition.\u003c/li\u003e\u003cli\u003e\nIgnition may be federated with Active Directory environments (e.g. OT \ndomains) by entering \u201cAuthentication Profile\u201d credentials within the \nIgnition gateway itself. This could use secure LDAP, SAML, or OpenID \nConnect.\u003c/li\u003e\u003cli\u003e\nWhen feasible, enforce strong credential management and MFA for all \nusers with Designer permissions (8.1.x and 8.3.x), Config Page \npermissions (8.1.x), and Config Write permissions (8.3.x).\u003c/li\u003e\u003cli\u003e\nWhen feasible, deploy Ignition within hardened or containerized environments.\n\n\u003c/li\u003e\u003c/ol\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003col\u003e\n\u003c/ol\u003e\n\u003cp\u003e\u003cbr\u003e\u003c/p\u003e\n\n\u003cbr\u003e"
            }
          ],
          "value": "Inductive Automation encourages users to do the following in order to reduce the risk of this vulnerability:\n\n  *  Create a new dedicated local Windows account that will be used \nexclusively for the Ignition service (e.g. svc-ign) (this should not be a\n domain account).\n  *  \nRemove all group memberships from the service account (including Users and Administrators).\n  *  Add to security policy to log in as a service.\n  *  Add to \u201cDeny log on locally\u201d security policy.\n  *  \nProvide full read/write access only to the Ignition installation directory for the service account created in step 1.\n  *  \nAdd read/write permissions to other directories in the local filesystem \nas needed (e.g: if configured to use optional Enterprise Administration \nModule to write automated backups to the file system).\n  *  \nSet deny access settings for service account on other directories not needed by the Ignition service.\n  *  \nSpecifically the C:\\Windows, C:\\Users, and directories for any other \napplications in the Program Files or Program Files (x86) directories.\n  *  \nUse java param to change temp directory to a location within the \nIgnition install directory so the Users folder can be denied access to \nthe Ignition service account.\n  *  \nRestrict project imports to verified and trusted sources only, ideally using checksums or digital signatures.\n  *  \nUse multiple environments (e.g. Dev, Test, Prod) with a staging workflow\n so that new data is never introduced directly to Production \nenvironments. See Ignition Deployment Best Practices.\n  *  \nWhen feasible, segment or isolate Ignition gateways from corporate resources and Windows Domains.\n  *  \nThe Ignition service account or AD server object should never need \nWindows Domain or Windows Active Directory privileges. This would only \nbe needed if an Asset Owners IT or OT department uses this for \nmanagement outside Ignition.\n  *  \nIgnition may be federated with Active Directory environments (e.g. OT \ndomains) by entering \u201cAuthentication Profile\u201d credentials within the \nIgnition gateway itself. This could use secure LDAP, SAML, or OpenID \nConnect.\n  *  \nWhen feasible, enforce strong credential management and MFA for all \nusers with Designer permissions (8.1.x and 8.3.x), Config Page \npermissions (8.1.x), and Config Write permissions (8.3.x).\n  *  \nWhen feasible, deploy Ignition within hardened or containerized environments."
        },
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cdiv\u003e\nMitigation guidance covering OS-level service account hardening for both\n Windows and Linux is available in Annex A of the Ignition Security \nHardening Guide. Application-level controls under a default installation\n are in development.\u003c/div\u003e"
            }
          ],
          "value": "Mitigation guidance covering OS-level service account hardening for both\n Windows and Linux is available in Annex A of the Ignition Security \nHardening Guide. Application-level controls under a default installation\n are in development."
        },
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "For more information and updates, users should refer to \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://security.inductiveautomation.com\"\u003eInductive Automation\u0027s Trust Portal\u003c/a\u003e."
            }
          ],
          "value": "For more information and updates, users should refer to  Inductive Automation\u0027s Trust Portal https://security.inductiveautomation.com ."
        }
      ],
      "x_generator": {
        "engine": "Vulnogram 0.5.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
    "assignerShortName": "icscert",
    "cveId": "CVE-2025-13911",
    "datePublished": "2025-12-18T20:24:30.118Z",
    "dateReserved": "2025-12-02T17:14:36.352Z",
    "dateUpdated": "2026-08-27T23:30:14.119Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2025-13911\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-12-18T20:44:32.471219Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-12-18T20:44:59.392Z\"}}], \"cna\": {\"title\": \"Inductive Automation Ignition Execution with Unnecessary Privileges\", \"source\": {\"advisory\": \"ICSA-25-352-01\", \"discovery\": \"EXTERNAL\"}, \"credits\": [{\"lang\": \"en\", \"type\": \"finder\", \"value\": \"Momen Eldawakhly of Samurai Digital Security Ltd reported this vulnerability to CISA.\"}, {\"lang\": \"en\", \"type\": \"finder\", \"value\": \"Ethan Thomason of CedarTech reported this vulnerability to CISA.\"}], \"metrics\": [{\"format\": \"CVSS\", \"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 6.4, \"attackVector\": \"ADJACENT_NETWORK\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H\", \"integrityImpact\": \"HIGH\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"HIGH\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"HIGH\", \"confidentialityImpact\": \"HIGH\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"GENERAL\"}]}, {\"format\": \"CVSS\", \"cvssV4_0\": {\"Safety\": \"NOT_DEFINED\", \"version\": \"4.0\", \"Recovery\": \"NOT_DEFINED\", \"baseScore\": 7.3, \"Automatable\": \"NOT_DEFINED\", \"attackVector\": \"ADJACENT\", \"baseSeverity\": \"HIGH\", \"valueDensity\": \"NOT_DEFINED\", \"vectorString\": \"CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N\", \"exploitMaturity\": \"NOT_DEFINED\", \"providerUrgency\": \"NOT_DEFINED\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"HIGH\", \"attackRequirements\": \"NONE\", \"privilegesRequired\": \"HIGH\", \"subIntegrityImpact\": \"NONE\", \"vulnIntegrityImpact\": \"HIGH\", \"subAvailabilityImpact\": \"NONE\", \"vulnAvailabilityImpact\": \"HIGH\", \"subConfidentialityImpact\": \"NONE\", \"vulnConfidentialityImpact\": \"HIGH\", \"vulnerabilityResponseEffort\": \"NOT_DEFINED\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"GENERAL\"}]}], \"affected\": [{\"vendor\": \"Inductive Automation\", \"product\": \"Ignition\", \"versions\": [{\"status\": \"affected\", \"version\": \"8.1.x\"}, {\"status\": \"affected\", \"version\": \"8.3.x\"}], \"defaultStatus\": \"unaffected\"}], \"references\": [{\"url\": \"https://security.inductiveautomation.com/\"}, {\"url\": \"https://www.cisa.gov/news-events/ics-advisories/icsa-25-352-01\"}, {\"url\": \"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-352-01.json\"}], \"workarounds\": [{\"lang\": \"en\", \"value\": \"Inductive Automation encourages users to do the following in order to reduce the risk of this vulnerability:\\n\\n  *  Create a new dedicated local Windows account that will be used \\nexclusively for the Ignition service (e.g. svc-ign) (this should not be a\\n domain account).\\n  *  \\nRemove all group memberships from the service account (including Users and Administrators).\\n  *  Add to security policy to log in as a service.\\n  *  Add to \\u201cDeny log on locally\\u201d security policy.\\n  *  \\nProvide full read/write access only to the Ignition installation directory for the service account created in step 1.\\n  *  \\nAdd read/write permissions to other directories in the local filesystem \\nas needed (e.g: if configured to use optional Enterprise Administration \\nModule to write automated backups to the file system).\\n  *  \\nSet deny access settings for service account on other directories not needed by the Ignition service.\\n  *  \\nSpecifically the C:\\\\Windows, C:\\\\Users, and directories for any other \\napplications in the Program Files or Program Files (x86) directories.\\n  *  \\nUse java param to change temp directory to a location within the \\nIgnition install directory so the Users folder can be denied access to \\nthe Ignition service account.\\n  *  \\nRestrict project imports to verified and trusted sources only, ideally using checksums or digital signatures.\\n  *  \\nUse multiple environments (e.g. Dev, Test, Prod) with a staging workflow\\n so that new data is never introduced directly to Production \\nenvironments. See Ignition Deployment Best Practices.\\n  *  \\nWhen feasible, segment or isolate Ignition gateways from corporate resources and Windows Domains.\\n  *  \\nThe Ignition service account or AD server object should never need \\nWindows Domain or Windows Active Directory privileges. This would only \\nbe needed if an Asset Owners IT or OT department uses this for \\nmanagement outside Ignition.\\n  *  \\nIgnition may be federated with Active Directory environments (e.g. OT \\ndomains) by entering \\u201cAuthentication Profile\\u201d credentials within the \\nIgnition gateway itself. This could use secure LDAP, SAML, or OpenID \\nConnect.\\n  *  \\nWhen feasible, enforce strong credential management and MFA for all \\nusers with Designer permissions (8.1.x and 8.3.x), Config Page \\npermissions (8.1.x), and Config Write permissions (8.3.x).\\n  *  \\nWhen feasible, deploy Ignition within hardened or containerized environments.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"\u003cp\u003eInductive Automation encourages users to do the following in order to reduce the risk of this vulnerability:\u003c/p\u003e\u003col\u003e\u003cli\u003eCreate a new dedicated local Windows account that will be used \\nexclusively for the Ignition service (e.g. svc-ign) (this should not be a\\n domain account).\u003c/li\u003e\u003cli\u003e\\nRemove all group memberships from the service account (including Users and Administrators).\u003c/li\u003e\u003cli\u003eAdd to security policy to log in as a service.\u003c/li\u003e\u003cli\u003eAdd to \\u201cDeny log on locally\\u201d security policy.\u003c/li\u003e\u003cli\u003e\\nProvide full read/write access only to the Ignition installation directory for the service account created in step 1.\u003c/li\u003e\u003cli\u003e\\nAdd read/write permissions to other directories in the local filesystem \\nas needed (e.g: if configured to use optional Enterprise Administration \\nModule to write automated backups to the file system).\u003c/li\u003e\u003cli\u003e\\nSet deny access settings for service account on other directories not needed by the Ignition service.\u003c/li\u003e\u003cli\u003e\\nSpecifically the C:\\\\Windows, C:\\\\Users, and directories for any other \\napplications in the Program Files or Program Files (x86) directories.\u003c/li\u003e\u003cli\u003e\\nUse java param to change temp directory to a location within the \\nIgnition install directory so the Users folder can be denied access to \\nthe Ignition service account.\u003c/li\u003e\u003cli\u003e\\nRestrict project imports to verified and trusted sources only, ideally using checksums or digital signatures.\u003c/li\u003e\u003cli\u003e\\nUse multiple environments (e.g. Dev, Test, Prod) with a staging workflow\\n so that new data is never introduced directly to Production \\nenvironments. See Ignition Deployment Best Practices.\u003c/li\u003e\u003cli\u003e\\nWhen feasible, segment or isolate Ignition gateways from corporate resources and Windows Domains.\u003c/li\u003e\u003cli\u003e\\nThe Ignition service account or AD server object should never need \\nWindows Domain or Windows Active Directory privileges. This would only \\nbe needed if an Asset Owners IT or OT department uses this for \\nmanagement outside Ignition.\u003c/li\u003e\u003cli\u003e\\nIgnition may be federated with Active Directory environments (e.g. OT \\ndomains) by entering \\u201cAuthentication Profile\\u201d credentials within the \\nIgnition gateway itself. This could use secure LDAP, SAML, or OpenID \\nConnect.\u003c/li\u003e\u003cli\u003e\\nWhen feasible, enforce strong credential management and MFA for all \\nusers with Designer permissions (8.1.x and 8.3.x), Config Page \\npermissions (8.1.x), and Config Write permissions (8.3.x).\u003c/li\u003e\u003cli\u003e\\nWhen feasible, deploy Ignition within hardened or containerized environments.\\n\\n\u003c/li\u003e\u003c/ol\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003col\u003e\\n\u003c/ol\u003e\\n\u003cp\u003e\u003cbr\u003e\u003c/p\u003e\\n\\n\u003cbr\u003e\", \"base64\": false}]}, {\"lang\": \"en\", \"value\": \"Mitigation guidance covering OS-level service account hardening for both\\n Windows and Linux is available in Annex A of the Ignition Security \\nHardening Guide. Application-level controls under a default installation\\n are in development.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"\u003cdiv\u003e\\nMitigation guidance covering OS-level service account hardening for both\\n Windows and Linux is available in Annex A of the Ignition Security \\nHardening Guide. Application-level controls under a default installation\\n are in development.\u003c/div\u003e\", \"base64\": false}]}, {\"lang\": \"en\", \"value\": \"For more information and updates, users should refer to  Inductive Automation\u0027s Trust Portal https://security.inductiveautomation.com .\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"For more information and updates, users should refer to \u003ca target=\\\"_blank\\\" rel=\\\"nofollow\\\" href=\\\"https://security.inductiveautomation.com\\\"\u003eInductive Automation\u0027s Trust Portal\u003c/a\u003e.\", \"base64\": false}]}], \"x_generator\": {\"engine\": \"Vulnogram 0.5.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"Ignition by Inductive Automation, when installed with default OS service\\n account settings, may expose the host system to an elevated code \\nexecution risk via the gateway backup restore functionality. An \\nauthenticated user with Gateway Administrator privileges can import a \\nmalicious gateway backup (.gwbk) file containing crafted project \\nresources, scripts, or modules, resulting in code execution on the host \\nsystem. This affects both Windows and Linux installations. On Windows, \\ndefault installations often run the Ignition service as NT \\nAUTHORITY\\\\SYSTEM, resulting in code execution with full local system \\nprivileges. On Linux, default installations commonly run the Ignition \\nservice as root or with elevated privileges. Specific privilege level \\ndepends on installation configuration.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"Ignition by Inductive Automation, when installed with default OS service\\n account settings, may expose the host system to an elevated code \\nexecution risk via the gateway backup restore functionality. An \\nauthenticated user with Gateway Administrator privileges can import a \\nmalicious gateway backup (.gwbk) file containing crafted project \\nresources, scripts, or modules, resulting in code execution on the host \\nsystem. This affects both Windows and Linux installations. On Windows, \\ndefault installations often run the Ignition service as NT \\nAUTHORITY\\\\SYSTEM, resulting in code execution with full local system \\nprivileges. On Linux, default installations commonly run the Ignition \\nservice as root or with elevated privileges. Specific privilege level \\ndepends on installation configuration.\", \"base64\": false}]}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-250\", \"description\": \"CWE-250\"}]}], \"providerMetadata\": {\"orgId\": \"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6\", \"shortName\": \"icscert\", \"dateUpdated\": \"2026-08-27T23:30:14.119Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2025-13911\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-27T23:30:14.119Z\", \"dateReserved\": \"2025-12-02T17:14:36.352Z\", \"assignerOrgId\": \"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6\", \"datePublished\": \"2025-12-18T20:24:30.118Z\", \"assignerShortName\": \"icscert\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…