Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-13911

Gravedad CVSS v4.0:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
18/12/2025
Última modificación:
19/12/2025

Descripción

*** Pendiente de traducción *** The vulnerability affects Ignition SCADA applications where Python <br /> scripting is utilized for automation purposes. The vulnerability arises <br /> from the absence of proper security controls that restrict which Python <br /> libraries can be imported and executed within the scripting environment.<br /> The core issue lies in the Ignition service account having system <br /> permissions beyond what an Ignition privileged user requires. When an <br /> authenticated administrator uploads a malicious project file containing <br /> Python scripts with bind shell capabilities, the application executes <br /> these scripts with the same privileges as the Ignition Gateway process, <br /> which typically runs with SYSTEM-level permissions on Windows. <br /> Alternative code execution patterns could lead to similar results.