Junglewise Threat Intelligence

CVE-2025-13913: Inductive Automation Ignition deserialization in file import

CVE-2025-13913 · Severity: medium · CVSS 6.3 · Published 2026-03-12

Executive brief

Inductive Automation Ignition, a platform used for industrial automation and SCADA systems, is vulnerable to a security flaw where a privileged user might inadvertently run malicious code. This occurs when a user with administrative access imports a specially crafted file into the system. If exploited, an attacker could gain the same operating system permissions as the Ignition service, potentially leading to unauthorized data access or disruption of industrial operations.

Technical details

A Deserialization of Untrusted Data vulnerability (CWE-502) exists in Inductive Automation Ignition versions prior to 8.3.0. The flaw is triggered when a privileged user imports an external file containing a specially crafted payload. Because the application does not safely deserialize this data, it can lead to arbitrary code execution with the permissions of the Ignition service account. The attack requires high privileges (PR:H) and user interaction (UI:R), and is typically restricted to the adjacent network (AV:A). Users are advised to upgrade to version 8.3.0 or greater and follow the vendor's security hardening guide to restrict service account permissions.

Affected products

  • Inductive Automation Ignition Software < 8.3.0

Timeline

  • 2026-03-12: advisory: CISA and NVD published the advisory.
  • 2026-03-12: disclosed
  • 2026-03-12: patched: Fix available in version 8.3.0.

References