CVE-2025-13911
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
18/12/2025
Last modified:
18/12/2025
Description
The vulnerability affects Ignition SCADA applications where Python <br />
scripting is utilized for automation purposes. The vulnerability arises <br />
from the absence of proper security controls that restrict which Python <br />
libraries can be imported and executed within the scripting environment.<br />
The core issue lies in the Ignition service account having system <br />
permissions beyond what an Ignition privileged user requires. When an <br />
authenticated administrator uploads a malicious project file containing <br />
Python scripts with bind shell capabilities, the application executes <br />
these scripts with the same privileges as the Ignition Gateway process, <br />
which typically runs with SYSTEM-level permissions on Windows. <br />
Alternative code execution patterns could lead to similar results.
Impact
Base Score 4.0
7.30
Severity 4.0
HIGH
Base Score 3.x
6.40
Severity 3.x
MEDIUM



