
TRC analysis shows CVE-2025-13911 in Ignition SCADA allows authenticated admins to execute Python scripts with SYSTEM privileges via malicious project imports. Attackers leveraged excessive service permissions for privilege escalation and lateral movement. Runtime segmentation helps contain post-compromise activity in industrial networks. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/inductive-automation-2025-authenticated-admin-python-script-execution
Post summary
The analysis reveals that CVE‑2025‑13911 permits authenticated admins to run privileged Python scripts through malicious project imports, and that attackers have actively exploited this for privilege escalation and lateral movement in Ignition SCADA.
