CVE-2025-13911

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
18/12/2025
Last modified:
18/12/2025

Description

The vulnerability affects Ignition SCADA applications where Python <br /> scripting is utilized for automation purposes. The vulnerability arises <br /> from the absence of proper security controls that restrict which Python <br /> libraries can be imported and executed within the scripting environment.<br /> The core issue lies in the Ignition service account having system <br /> permissions beyond what an Ignition privileged user requires. When an <br /> authenticated administrator uploads a malicious project file containing <br /> Python scripts with bind shell capabilities, the application executes <br /> these scripts with the same privileges as the Ignition Gateway process, <br /> which typically runs with SYSTEM-level permissions on Windows. <br /> Alternative code execution patterns could lead to similar results.