{"id":"CVE-2025-13911","title":"Ignition by Inductive Automation, when installed with default OS service\n account settings, may expose the host system to an elevated code \nexecution risk via the gateway backup restore functionality","summary":"Ignition by Inductive Automation, when installed with default OS service\n account settings, may expose the host system to an elevated code \nexecution risk via the gateway backup restore functionality. An \nauthenticated user with Gateway …","severity":"medium","cvss":6.4,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-250"],"published":"2025-12-18","updated":"2026-08-28","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-13911","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-352-01.json","label":"ics-cert@hq.dhs.gov"},{"url":"https://security.inductiveautomation.com/","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-25-352-01","label":"ics-cert@hq.dhs.gov"}],"tags":["nvd"],"epss":0.00253,"epssPercentile":0.14975,"ingestedAt":"2026-08-28T03:12:32.500Z","slug":"CVE-2025-13911","body":"## Overview\n\nIgnition by Inductive Automation, when installed with default OS service\n account settings, may expose the host system to an elevated code \nexecution risk via the gateway backup restore functionality. An \nauthenticated user with Gateway Administrator privileges can import a \nmalicious gateway backup (.gwbk) file containing crafted project \nresources, scripts, or modules, resulting in code execution on the host \nsystem. This affects both Windows and Linux installations. On Windows, \ndefault installations often run the Ignition service as NT \nAUTHORITY\\SYSTEM, resulting in code execution with full local system \nprivileges. On Linux, default installations commonly run the Ignition \nservice as root or with elevated privileges. Specific privilege level \ndepends on installation configuration.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":35.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}