{"api_version":"1","generated_at":"2026-08-28T03:53:54+00:00","cve":"CVE-2025-13911","urls":{"html":"https://cve.report/CVE-2025-13911","api":"https://cve.report/api/cve/CVE-2025-13911.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-13911","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-13911"},"summary":{"title":"Inductive Automation Ignition Execution with Unnecessary Privileges","description":"Ignition by Inductive Automation, when installed with default OS service\n account settings, may expose the host system to an elevated code \nexecution risk via the gateway backup restore functionality. An \nauthenticated user with Gateway Administrator privileges can import a \nmalicious gateway backup (.gwbk) file containing crafted project \nresources, scripts, or modules, resulting in code execution on the host \nsystem. This affects both Windows and Linux installations. On Windows, \ndefault installations often run the Ignition service as NT \nAUTHORITY\\SYSTEM, resulting in code execution with full local system \nprivileges. On Linux, default installations commonly run the Ignition \nservice as root or with elevated privileges. Specific privilege level \ndepends on installation configuration.","state":"PUBLISHED","assigner":"icscert","published_at":"2025-12-18 21:15:52","updated_at":"2026-08-28 02:16:19"},"problem_types":["CWE-250","CWE-250 CWE-250"],"metrics":[{"version":"4.0","source":"ics-cert@hq.dhs.gov","type":"Secondary","score":"7.3","severity":"HIGH","vector":"CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"ADJACENT","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"7.3","severity":"HIGH","vector":"CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":7.3,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"HIGH","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"}},{"version":"3.1","source":"ics-cert@hq.dhs.gov","type":"Secondary","score":"6.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"HIGH","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":6.4,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://security.inductiveautomation.com/","name":"https://security.inductiveautomation.com/","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-352-01.json","name":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-352-01.json","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-25-352-01","name":"https://www.cisa.gov/news-events/ics-advisories/icsa-25-352-01","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-13911","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-13911","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Inductive Automation","product":"Ignition","version":"affected 8.1.x","platforms":[]},{"source":"CNA","vendor":"Inductive Automation","product":"Ignition","version":"affected 8.3.x","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"Inductive Automation encourages users to do the following in order to reduce the risk of this vulnerability:\n\n  *  Create a new dedicated local Windows account that will be used \nexclusively for the Ignition service (e.g. svc-ign) (this should not be a\n domain account).\n  *  \nRemove all group memberships from the service account (including Users and Administrators).\n  *  Add to security policy to log in as a service.\n  *  Add to “Deny log on locally” security policy.\n  *  \nProvide full read/write access only to the Ignition installation directory for the service account created in step 1.\n  *  \nAdd read/write permissions to other directories in the local filesystem \nas needed (e.g: if configured to use optional Enterprise Administration \nModule to write automated backups to the file system).\n  *  \nSet deny access settings for service account on other directories not needed by the Ignition service.\n  *  \nSpecifically the C:\\Windows, C:\\Users, and directories for any other \napplications in the Program Files or Program Files (x86) directories.\n  *  \nUse java param to change temp directory to a location within the \nIgnition install directory so the Users folder can be denied access to \nthe Ignition service account.\n  *  \nRestrict project imports to verified and trusted sources only, ideally using checksums or digital signatures.\n  *  \nUse multiple environments (e.g. Dev, Test, Prod) with a staging workflow\n so that new data is never introduced directly to Production \nenvironments. See Ignition Deployment Best Practices.\n  *  \nWhen feasible, segment or isolate Ignition gateways from corporate resources and Windows Domains.\n  *  \nThe Ignition service account or AD server object should never need \nWindows Domain or Windows Active Directory privileges. This would only \nbe needed if an Asset Owners IT or OT department uses this for \nmanagement outside Ignition.\n  *  \nIgnition may be federated with Active Directory environments (e.g. OT \ndomains) by entering “Authentication Profile” credentials within the \nIgnition gateway itself. This could use secure LDAP, SAML, or OpenID \nConnect.\n  *  \nWhen feasible, enforce strong credential management and MFA for all \nusers with Designer permissions (8.1.x and 8.3.x), Config Page \npermissions (8.1.x), and Config Write permissions (8.3.x).\n  *  \nWhen feasible, deploy Ignition within hardened or containerized environments.","time":"","lang":"en"},{"source":"CNA","title":"","value":"Mitigation guidance covering OS-level service account hardening for both\n Windows and Linux is available in Annex A of the Ignition Security \nHardening Guide. Application-level controls under a default installation\n are in development.","time":"","lang":"en"},{"source":"CNA","title":"","value":"For more information and updates, users should refer to  Inductive Automation's Trust Portal https://security.inductiveautomation.com .","time":"","lang":"en"}],"exploits":[],"credits":[{"source":"CNA","value":"Momen Eldawakhly of Samurai Digital Security Ltd reported this vulnerability to CISA.","lang":"en"},{"source":"CNA","value":"Ethan Thomason of CedarTech reported this vulnerability to CISA.","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-13911","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2025-12-18T20:44:32.471219Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2025-12-18T20:45:07.276Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Ignition","vendor":"Inductive Automation","versions":[{"status":"affected","version":"8.1.x"},{"status":"affected","version":"8.3.x"}]}],"credits":[{"lang":"en","type":"finder","value":"Momen Eldawakhly of Samurai Digital Security Ltd reported this vulnerability to CISA."},{"lang":"en","type":"finder","value":"Ethan Thomason of CedarTech reported this vulnerability to CISA."}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Ignition by Inductive Automation, when installed with default OS service\n account settings, may expose the host system to an elevated code \nexecution risk via the gateway backup restore functionality. An \nauthenticated user with Gateway Administrator privileges can import a \nmalicious gateway backup (.gwbk) file containing crafted project \nresources, scripts, or modules, resulting in code execution on the host \nsystem. This affects both Windows and Linux installations. On Windows, \ndefault installations often run the Ignition service as NT \nAUTHORITY\\SYSTEM, resulting in code execution with full local system \nprivileges. On Linux, default installations commonly run the Ignition \nservice as root or with elevated privileges. Specific privilege level \ndepends on installation configuration."}],"value":"Ignition by Inductive Automation, when installed with default OS service\n account settings, may expose the host system to an elevated code \nexecution risk via the gateway backup restore functionality. An \nauthenticated user with Gateway Administrator privileges can import a \nmalicious gateway backup (.gwbk) file containing crafted project \nresources, scripts, or modules, resulting in code execution on the host \nsystem. This affects both Windows and Linux installations. On Windows, \ndefault installations often run the Ignition service as NT \nAUTHORITY\\SYSTEM, resulting in code execution with full local system \nprivileges. On Linux, default installations commonly run the Ignition \nservice as root or with elevated privileges. Specific privilege level \ndepends on installation configuration."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":6.4,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":7.3,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"HIGH","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-250","description":"CWE-250","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-27T23:30:14.119Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"url":"https://security.inductiveautomation.com/"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-25-352-01"},{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-352-01.json"}],"source":{"advisory":"ICSA-25-352-01","discovery":"EXTERNAL"},"title":"Inductive Automation Ignition Execution with Unnecessary Privileges","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Inductive Automation encourages users to do the following in order to reduce the risk of this vulnerability:</p><ol><li>Create a new dedicated local Windows account that will be used \nexclusively for the Ignition service (e.g. svc-ign) (this should not be a\n domain account).</li><li>\nRemove all group memberships from the service account (including Users and Administrators).</li><li>Add to security policy to log in as a service.</li><li>Add to “Deny log on locally” security policy.</li><li>\nProvide full read/write access only to the Ignition installation directory for the service account created in step 1.</li><li>\nAdd read/write permissions to other directories in the local filesystem \nas needed (e.g: if configured to use optional Enterprise Administration \nModule to write automated backups to the file system).</li><li>\nSet deny access settings for service account on other directories not needed by the Ignition service.</li><li>\nSpecifically the C:\\Windows, C:\\Users, and directories for any other \napplications in the Program Files or Program Files (x86) directories.</li><li>\nUse java param to change temp directory to a location within the \nIgnition install directory so the Users folder can be denied access to \nthe Ignition service account.</li><li>\nRestrict project imports to verified and trusted sources only, ideally using checksums or digital signatures.</li><li>\nUse multiple environments (e.g. Dev, Test, Prod) with a staging workflow\n so that new data is never introduced directly to Production \nenvironments. See Ignition Deployment Best Practices.</li><li>\nWhen feasible, segment or isolate Ignition gateways from corporate resources and Windows Domains.</li><li>\nThe Ignition service account or AD server object should never need \nWindows Domain or Windows Active Directory privileges. This would only \nbe needed if an Asset Owners IT or OT department uses this for \nmanagement outside Ignition.</li><li>\nIgnition may be federated with Active Directory environments (e.g. OT \ndomains) by entering “Authentication Profile” credentials within the \nIgnition gateway itself. This could use secure LDAP, SAML, or OpenID \nConnect.</li><li>\nWhen feasible, enforce strong credential management and MFA for all \nusers with Designer permissions (8.1.x and 8.3.x), Config Page \npermissions (8.1.x), and Config Write permissions (8.3.x).</li><li>\nWhen feasible, deploy Ignition within hardened or containerized environments.\n\n</li></ol><div><br></div><ol>\n</ol>\n<p><br></p>\n\n<br>"}],"value":"Inductive Automation encourages users to do the following in order to reduce the risk of this vulnerability:\n\n  *  Create a new dedicated local Windows account that will be used \nexclusively for the Ignition service (e.g. svc-ign) (this should not be a\n domain account).\n  *  \nRemove all group memberships from the service account (including Users and Administrators).\n  *  Add to security policy to log in as a service.\n  *  Add to “Deny log on locally” security policy.\n  *  \nProvide full read/write access only to the Ignition installation directory for the service account created in step 1.\n  *  \nAdd read/write permissions to other directories in the local filesystem \nas needed (e.g: if configured to use optional Enterprise Administration \nModule to write automated backups to the file system).\n  *  \nSet deny access settings for service account on other directories not needed by the Ignition service.\n  *  \nSpecifically the C:\\Windows, C:\\Users, and directories for any other \napplications in the Program Files or Program Files (x86) directories.\n  *  \nUse java param to change temp directory to a location within the \nIgnition install directory so the Users folder can be denied access to \nthe Ignition service account.\n  *  \nRestrict project imports to verified and trusted sources only, ideally using checksums or digital signatures.\n  *  \nUse multiple environments (e.g. Dev, Test, Prod) with a staging workflow\n so that new data is never introduced directly to Production \nenvironments. See Ignition Deployment Best Practices.\n  *  \nWhen feasible, segment or isolate Ignition gateways from corporate resources and Windows Domains.\n  *  \nThe Ignition service account or AD server object should never need \nWindows Domain or Windows Active Directory privileges. This would only \nbe needed if an Asset Owners IT or OT department uses this for \nmanagement outside Ignition.\n  *  \nIgnition may be federated with Active Directory environments (e.g. OT \ndomains) by entering “Authentication Profile” credentials within the \nIgnition gateway itself. This could use secure LDAP, SAML, or OpenID \nConnect.\n  *  \nWhen feasible, enforce strong credential management and MFA for all \nusers with Designer permissions (8.1.x and 8.3.x), Config Page \npermissions (8.1.x), and Config Write permissions (8.3.x).\n  *  \nWhen feasible, deploy Ignition within hardened or containerized environments."},{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<div>\nMitigation guidance covering OS-level service account hardening for both\n Windows and Linux is available in Annex A of the Ignition Security \nHardening Guide. Application-level controls under a default installation\n are in development.</div>"}],"value":"Mitigation guidance covering OS-level service account hardening for both\n Windows and Linux is available in Annex A of the Ignition Security \nHardening Guide. Application-level controls under a default installation\n are in development."},{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"For more information and updates, users should refer to <a target=\"_blank\" rel=\"nofollow\" href=\"https://security.inductiveautomation.com\">Inductive Automation's Trust Portal</a>."}],"value":"For more information and updates, users should refer to  Inductive Automation's Trust Portal https://security.inductiveautomation.com ."}],"x_generator":{"engine":"Vulnogram 0.5.0"}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2025-13911","datePublished":"2025-12-18T20:24:30.118Z","dateReserved":"2025-12-02T17:14:36.352Z","dateUpdated":"2026-08-27T23:30:14.119Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2025-12-18 21:15:52","lastModifiedDate":"2026-08-28 02:16:19","problem_types":["CWE-250","CWE-250 CWE-250"],"metrics":{"cvssMetricV40":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"ADJACENT","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.5,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-18T20:44:32.471219Z","id":"CVE-2025-13911","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"13911","Ordinal":"1","Title":"Inductive Automation Ignition Execution with Unnecessary Privile","CVE":"CVE-2025-13911","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"13911","Ordinal":"1","NoteData":"Ignition by Inductive Automation, when installed with default OS service\n account settings, may expose the host system to an elevated code \nexecution risk via the gateway backup restore functionality. An \nauthenticated user with Gateway Administrator privileges can import a \nmalicious gateway backup (.gwbk) file containing crafted project \nresources, scripts, or modules, resulting in code execution on the host \nsystem. This affects both Windows and Linux installations. On Windows, \ndefault installations often run the Ignition service as NT \nAUTHORITY\\SYSTEM, resulting in code execution with full local system \nprivileges. On Linux, default installations commonly run the Ignition \nservice as root or with elevated privileges. Specific privilege level \ndepends on installation configuration.","Type":"Description","Title":"Inductive Automation Ignition Execution with Unnecessary Privile"}]}}}