CVE-2025-13911Active Exploitation

LOWCVSS 7.3 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Ignition by Inductive Automation, when installed with default OS service account settings, may expose the host system to an elevated code execution risk via the gateway backup restore functionality. An authenticated user with Gateway Administrator privileges can import a malicious gateway backup (.gwbk) file containing crafted project resources, scripts, or modules, resulting in code execution on the host system. This affects both Windows and Linux installations. On Windows, default installations often run the Ignition service as NT AUTHORITY\SYSTEM, resulting in code execution with full local system privileges. On Linux, default installations commonly run the Ignition service as root or with elevated privileges. Specific privilege level depends on installation configuration.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-250

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-13: 1Active Exploitation · 2026-03-13: 1Technical Details · 2026-03-13: 103-13
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows CVE-2025-13911 in Ignition SCADA allows authenticated admins to execute Python scripts with SYSTEM privileges via malicious project imports. Attackers leveraged excessive service permissions for privilege escalation and lateral movement. Runtime segmentation helps contain post-compromise activity in industrial networks. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/inductive-automation-2025-authenticated-admin-python-script-execution

    Post summary

    The analysis reveals that CVE‑2025‑13911 permits authenticated admins to run privileged Python scripts through malicious project imports, and that attackers have actively exploited this for privilege escalation and lateral movement in Ignition SCADA.

    00000158
    1.9K followersView on X

Explore more