Junglewise Threat Intelligence

CVE-2025-13911: Inductive Automation Ignition code execution via gateway backup restore

CVE-2025-13911 · Severity: medium · CVSS 6.4 · Published 2025-12-18

Technologies: Inductive Automation Ignition.

Executive brief

Ignition is industrial automation software used to control and monitor manufacturing and operational technology systems. When running with default service account settings (common in production deployments), authenticated administrators can import malicious backup files that execute arbitrary code with system-level privileges, potentially compromising the entire host system and any connected industrial equipment or networks.

Technical details

The vulnerability exists in Ignition's gateway backup restore functionality, which fails to properly validate or sanitize project resources, scripts, or modules imported from .gwbk backup files. An authenticated user with Gateway Administrator privileges can craft a malicious backup file containing weaponized code that executes during the restore process. The attack requires authentication and administrative access, but on Windows systems running with default NT AUTHORITY\SYSTEM privileges or Linux systems running as root, the resulting code execution carries full system privileges. No patch is explicitly mentioned in the advisory; the remediation appears to be changing the service account to run with reduced privileges.

Affected products

  • Inductive Automation Ignition

Timeline

  • 2025-12-18: disclosed: CVE-2025-13911 published
  • 2025-12-18: advisory: CISA alert icsa-25-352-01 issued

References