CVE-2025-13911
The vulnerability affects Ignition SCADA applications where Python scripting is utilized for automation purposes. The vulnerability arises from the absence of proper security controls that restrict which Python libraries can be imported and executed within the scripting environment. The core issue lies in the Ignition service account having system permissions beyond what an Ignition privileged user requires. When an authenticated administrator uploads a malicious project file containing Python scripts with bind shell capabilities, the application executes these scripts with the same privileges as the Ignition Gateway process, which typically runs with SYSTEM-level permissions on Windows. Alternative code execution patterns could lead to similar results.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.3
- CVSS vector
- CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.25%
- CWE
- CWE-250
- Published
- 2025-12-18
- Last modified
- 2026-08-28
Affected products
- Inductive Automation Ignition
- Inductive Automation Ignition
Weakness type
Related vulnerabilities
- CVE-2024-38813 — Privilege escalation vulnerability
- CVE-2026-4606 — GeoVision ERM Improper Privilege Assignment Leads to SYSTEM-Level Privilege
- CVE-2025-32445 — Users can gain privileged access to the host system and cluster with EventSource and Sensor CR
- CVE-2024-8767 — Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected
- CVE-2025-33224 — NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges.
- CVE-2025-33223 — NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges.
- CVE-2025-13375 — IBM Common Cryptographic Architecture Arbitrary Command Execution
- CVE-2024-7102 — Execution with Unnecessary Privileges in GitLab