CVE-2025-13911
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
18/12/2025
Last modified:
28/08/2026
Description
Ignition by Inductive Automation, when installed with default OS service<br />
account settings, may expose the host system to an elevated code <br />
execution risk via the gateway backup restore functionality. An <br />
authenticated user with Gateway Administrator privileges can import a <br />
malicious gateway backup (.gwbk) file containing crafted project <br />
resources, scripts, or modules, resulting in code execution on the host <br />
system. This affects both Windows and Linux installations. On Windows, <br />
default installations often run the Ignition service as NT <br />
AUTHORITY\SYSTEM, resulting in code execution with full local system <br />
privileges. On Linux, default installations commonly run the Ignition <br />
service as root or with elevated privileges. Specific privilege level <br />
depends on installation configuration.
Impact
Base Score 4.0
7.30
Severity 4.0
HIGH
Base Score 3.x
6.40
Severity 3.x
MEDIUM


